THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-h89q-4j2h-7h88 (high) — SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content

[GHSA] GHSA-h89q-4j2h-7h88 (high) — SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content

medgithub_advisoriesPublished 2026-09-02

GHSA-h89q-4j2h-7h88 Severity: high CVE: CVE-2026-59834

SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content

## Summary

Siyuan's block search endpoint concatenates attacker-controlled `paths[]` values into SQL predicates used by non-SQL search modes. Through Siyuan's publish service, an unauthenticated visitor is forwarded to the kernel with a reader-role token and can rea

Indicators of compromise

Original source: https://github.com/advisories/GHSA-h89q-4j2h-7h88