THREAT OPS › Threat News › [GHSA] GHSA-vh22-h7hf-www7 (critical) — SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write
[GHSA] GHSA-vh22-h7hf-www7 (critical) — SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write
GHSA-vh22-h7hf-www7 Severity: critical CVE: CVE-2026-69084
SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write
**CVE:** This vulnerability corresponds to CVE-2026-69084.
### Summary
The `/api/search/searchEmbedBlock` endpoint passes
Indicators of compromise
- CVE-2026-69084cve
- http://127.0.0.1:6806/api/system/versionurl
- http://127.0.0.1:6806/api/setting/setPublishurl
- http://127.0.0.1:6808/api/search/fullTextSearchBlockurl
- http://127.0.0.1:6808/api/search/searchEmbedBlockurl
Original source: https://github.com/advisories/GHSA-vh22-h7hf-www7