GitHub Security Advisory (GHSA-x67c-8pwr-m8g3)Vendor advisory
https://github.com/siyuan-note/siyuan/security/advisories/GHSA-x67c-8pwr-m8g3 CVE-2026-72807
HIGH
SiYuan before v3.7.4 SQL Injection via queryBlocks template
Record summary
CVE-2026-72807 has a selected CVSS score of 8.8 (high).
Description
SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template columns that expose the queryBlocks function, which executes raw SQL using string substitution instead of parameterized queries. Attackers can distribute malicious SiYuan documents or packages with crafted template columns that execute arbitrary SQL on a victim's kernel when the package is imported and rendered, enabling read and write access across notebooks.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 12, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Before 3.7.4 | affected |
| 3.7.4 | unaffected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-72807 VulnCheck Advisory: SiYuan before v3.7.4 SQL Injection via queryBlocks templateThird-party advisory
https://www.vulncheck.com/advisories/siyuan-before-sql-injection-via-queryblocks-template