THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-x67c-8pwr-m8g3 (high) — SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel

[GHSA] GHSA-x67c-8pwr-m8g3 (high) — SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel

medgithub_advisoriesPublished 2026-09-03

GHSA-x67c-8pwr-m8g3 Severity: high CVE: CVE-2026-72807

SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel

**CVE:** This vulnerability corresponds to CVE-2026-72807.

### Summary

Attribute-view (AV) template columns are live-evaluated on every rend

Indicators of compromise

Original source: https://github.com/advisories/GHSA-x67c-8pwr-m8g3