THREAT OPS › Threat News › [GHSA] GHSA-h89q-4j2h-7h88 (high) — SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content
[GHSA] GHSA-h89q-4j2h-7h88 (high) — SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content
GHSA-h89q-4j2h-7h88 Severity: high CVE: CVE-2026-59834
SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content
## Summary
Siyuan's block search endpoint concatenates attacker-controlled `paths[]` values into SQL predicates used by non-SQL search modes. Through Siyuan's publish service, an unauthenticated visitor is forwarded to the kernel with a reader-role token and can rea
Indicators of compromise
- CVE-2026-59834cve
Original source: https://github.com/advisories/GHSA-h89q-4j2h-7h88