CVE-2026-69083
CRITICALSiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-69083. PoCs published by 0xdak.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated SQL injection vulnerability (CVE-2026-69083) in SiYuan < 3.7.3 via the `/api/search/fullTextSearchAssetContent` endpoint. The PoC exploits improper string concatenation in a REGEXP clause to dump the asset-content SQLite database, enabling data exfiltration.
Description
SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. Attackers can execute arbitrary SQL on the read-write asset-content database via unescaped method parameters and REGEXP clauses to read, modify, or delete cross-notebook data.
Exploits (1)
This exploit demonstrates an unauthenticated SQL injection vulnerability (CVE-2026-69083) in SiYuan < 3.7.3 via the `/api/search/fullTextSearchAssetContent` endpoint. The PoC exploits improper string concatenation in a REGEXP clause to dump the asset-content SQLite database, enabling data exfiltration.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N