THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-vh22-h7hf-www7 (critical) — SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write

[GHSA] GHSA-vh22-h7hf-www7 (critical) — SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write

highgithub_advisoriesPublished 2026-09-03

GHSA-vh22-h7hf-www7 Severity: critical CVE: CVE-2026-69084

SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write

**CVE:** This vulnerability corresponds to CVE-2026-69084.

### Summary

The `/api/search/searchEmbedBlock` endpoint passes

Indicators of compromise

Original source: https://github.com/advisories/GHSA-vh22-h7hf-www7