{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/kernel--0.0.0-20260723035036-0a176345e02a/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:siyuan_note:siyuan:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8,"id":"CVE-2026-72807"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["kernel (\u003c 0.0.0-20260723035036-0a176345e02a)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","ssti","sql-injection","rce"],"_cs_type":"advisory","_cs_vendors":["SiYuan"],"content_html":"\u003cp\u003eSiYuan note-taking software is susceptible to a second-order Server-Side Template Injection (SSTI) vulnerability, tracked as CVE-2026-72807. The vulnerability exists within Attribute-View (AV) template columns, which are live-evaluated during rendering. The \u003ccode\u003equeryBlocks\u003c/code\u003e template function, intended for database interaction, fails to use parameterized queries, instead performing raw string substitution into SQL statements.\u003c/p\u003e\n\u003cp\u003eWhile AV creation is restricted to administrators, the injection is delivered as a second-order threat. An attacker can craft a document or an AV package containing a malicious template column. When a victim imports this package and renders the associated Attribute-View, the malicious template executes arbitrary SQL against the application's read-write database handle. This allows for unauthorized data access across notebooks and potential write operations via statement stacking. The vulnerability affects the SiYuan kernel prior to version 0.0.0-20260723035036-0a176345e02a.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker constructs a SiYuan document or AV package containing a template column using the \u003ccode\u003equeryBlocks\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eThe attacker injects malicious SQL commands as an argument to \u003ccode\u003equeryBlocks\u003c/code\u003e (e.g., \u003ccode\u003e.action{range queryBlocks \u0026quot;SELECT * FROM blocks...\u0026quot;}\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe malicious document or AV package is distributed to a victim via file import.\u003c/li\u003e\n\u003cli\u003eThe victim imports the document into their local SiYuan instance.\u003c/li\u003e\n\u003cli\u003eThe victim triggers the rendering of the Attribute-View (e.g., via \u003ccode\u003ePOST /api/av/renderAttributeView\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe SiYuan kernel evaluates the template, substituting the malicious SQL string directly into the database query.\u003c/li\u003e\n\u003cli\u003eThe SQLite engine executes the arbitrary SQL commands, potentially exfiltrating data or modifying the database.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to unauthorized access to the victim's local SiYuan database. Because the \u003ccode\u003equeryBlocks\u003c/code\u003e function operates on a read-write database handle, an attacker can bypass access controls to read sensitive notes or perform write operations if statement stacking is supported by the SQLite implementation. The severity is bounded by the requirement for victim interaction (importing and rendering content).\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the SiYuan kernel to version 0.0.0-20260723035036-0a176345e02a or later to resolve CVE-2026-72807.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation and sanitization for all imported document content and AV templates.\u003c/li\u003e\n\u003cli\u003eReplace raw string substitution in the \u003ccode\u003equeryBlocks\u003c/code\u003e function with proper parameterized query bindings.\u003c/li\u003e\n\u003cli\u003eReview and restrict the set of template functions available within Attribute-View columns to prevent access to dangerous primitives.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-04T00:04:41Z","date_published":"2026-09-04T00:04:41Z","id":"https://feed.craftedsignal.io/briefs/2026-09-siyuan-ssti/","summary":"SiYuan kernel is vulnerable to a second-order SSTI via the queryBlocks template function, allowing attackers to achieve arbitrary SQL execution upon rendering imported malicious content.","title":"Second-Order SSTI in SiYuan via Attribute-View Template Columns","url":"https://feed.craftedsignal.io/briefs/2026-09-siyuan-ssti/"}],"language":"en","title":"CraftedSignal Threat Feed - Kernel (\u003c 0.0.0-20260723035036-0a176345e02a)","version":"https://jsonfeed.org/version/1.1"}