What is CVE-2026-69083?
SiYuan versions before v3.7.3 contain an SQL injection vulnerability in the fullTextSearchAssetContent endpoint, exploitable by unauthenticated users with published RoleReader tokens. Attackers can execute arbitrary SQL on the asset-content database. Affected users should immediately upgrade to version v3.7.3 or later.
Azərbaycanca: SiYuan proqramının v3.7.3-dən əvvəlki versiyalarında fullTextSearchAssetContent endpointində autentifikasiya olunmamış istifadəçilər tərəfindən istismar edilə bilən SQL injection zəifliyi aşkarlanıb. Bu zəiflik vasitəsilə təcavüzkarlar asset-content bazasında ixtiyari SQL əmrləri icra edə bilər. SiYuan istifadəçiləri dərhal v3.7.3 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: SiYuan
FAQ2
Which versions of SiYuan are affected by the CVE-2026-69083 SQL injection vulnerability?
SiYuan versions before v3.7.3 are affected by this vulnerability.
How can I protect against CVE-2026-69083?
You should immediately upgrade SiYuan to version v3.7.3 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.