CVE-2026-69083: Siyuan-Note Siyuan

Critical severity, CVSS 10.0. EPSS: 0.5% chance of exploitation in the next 30 days.

SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. Attackers can execute arbitrary SQL on the read-write asset-content database via unescaped method parameters and REGEXP clauses to read, modify, or delete cross-notebook data.

Affected products

Published 2026-08-03. Last modified 2026-08-26.