THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-fph3-ghq9-vw66 (critical) — SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB

[GHSA] GHSA-fph3-ghq9-vw66 (critical) — SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB

highgithub_advisoriesPublished 2026-09-03

GHSA-fph3-ghq9-vw66 Severity: critical CVE: CVE-2026-69083

SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB

**CVE:** This vulnerability corresponds to CVE-2026-69083.

### Summary

The `/api/

Indicators of compromise

Original source: https://github.com/advisories/GHSA-fph3-ghq9-vw66