THREAT OPS › Threat News › [GHSA] GHSA-q2vg-7qgx-x5fc (critical) — SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle
[GHSA] GHSA-q2vg-7qgx-x5fc (critical) — SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle
GHSA-q2vg-7qgx-x5fc Severity: critical CVE: CVE-2026-72811
SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle
**CVE:** This vulnerability corresponds to CVE-2026-72811.
### Summary
The backlink
Indicators of compromise
- CVE-2026-72811cve
- http://127.0.0.1:6808/api/ref/getBacklink2url
Original source: https://github.com/advisories/GHSA-q2vg-7qgx-x5fc