THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-q2vg-7qgx-x5fc (critical) — SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle

[GHSA] GHSA-q2vg-7qgx-x5fc (critical) — SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle

highgithub_advisoriesPublished 2026-09-03

GHSA-q2vg-7qgx-x5fc Severity: critical CVE: CVE-2026-72811

SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle

**CVE:** This vulnerability corresponds to CVE-2026-72811.

### Summary

The backlink

Indicators of compromise

Original source: https://github.com/advisories/GHSA-q2vg-7qgx-x5fc