THREAT OPS › Threat News › [GHSA] GHSA-fph3-ghq9-vw66 (critical) — SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB
[GHSA] GHSA-fph3-ghq9-vw66 (critical) — SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB
GHSA-fph3-ghq9-vw66 Severity: critical CVE: CVE-2026-69083
SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB
**CVE:** This vulnerability corresponds to CVE-2026-69083.
### Summary
The `/api/
Indicators of compromise
- CVE-2026-69083cve
- http://127.0.0.1:6806/api/notebook/createNotebookurl
- http://127.0.0.1:6806/api/filetree/createDocWithMdurl
- http://127.0.0.1:6806/api/fintent-Type:url
- http://127.0.0.1:6806/api/query/sqlurl
- http://127.0.0.1:6806/api/filetree/setPublishAccessurl
- http://127.0.0.1:6808/api/block/getBlockDOMurl
- http://127.0.0.1:6808/api/block/getHeadingChildrenDOMurl
Original source: https://github.com/advisories/GHSA-fph3-ghq9-vw66