{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-69086/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":10,"id":"CVE-2026-69083"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SiYuan (\u003c 3.7.3)"],"_cs_severities":["critical"],"_cs_tags":["sql-injection","web-vulnerability","path-traversal","cve-2026-69086","web-application"],"_cs_type":"advisory","_cs_vendors":["siyuan-note"],"content_html":"\u003cp\u003eSiYuan versions prior to 3.7.3 are vulnerable to an unauthenticated SQL injection vulnerability located in the fullTextSearchAssetContent endpoint. The vulnerability is caused by improper neutralization of special elements in input parameters, specifically when processing REGEXP clauses. An unauthenticated attacker can exploit this flaw to execute arbitrary SQL commands against the read-write asset-content database. This allows for unauthorized reading, modification, or deletion of stored notebook data. The vulnerability is considered high-risk due to the lack of required authentication and the potential for full data compromise within the application environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to perform unauthorized operations on the SiYuan database. This can result in complete loss of confidentiality and integrity for user data stored within notebooks, including the potential for mass data deletion or unauthorized exfiltration of sensitive information across all notebooks managed by the instance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all SiYuan installations to version 3.7.3 or later immediately to resolve the vulnerability documented in CVE-2026-69083.\u003c/li\u003e\n\u003cli\u003eImplement strict ingress filtering for the application, specifically restricting access to the fullTextSearchAssetContent API endpoint from untrusted networks.\u003c/li\u003e\n\u003cli\u003eReview webserver logs for requests to the fullTextSearchAssetContent endpoint containing SQL injection markers, such as unexpected use of semicolon, comments, or REGEXP keywords in query parameters.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-03T16:06:08Z","date_published":"2026-08-03T16:04:30Z","id":"https://feed.craftedsignal.io/briefs/2026-08-siyuan-sqli/","summary":"SiYuan versions before 3.7.3 contain a critical SQL injection vulnerability in the fullTextSearchAssetContent endpoint, allowing unauthenticated attackers to execute arbitrary SQL commands on the backend asset-content database.","title":"SQL Injection in SiYuan fullTextSearchAssetContent Endpoint","url":"https://feed.craftedsignal.io/briefs/2026-08-siyuan-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-69086","version":"https://jsonfeed.org/version/1.1"}