CVE-2026-101091: fallo de gravedad alta en siyuan-note siyuan
SiYuan before v3.8.4 SQL Injection via Block Query Embed
Publicada el · Actualizada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.1epss 0.3%
probabilidad de explotación
0.3%top 84% de las CVE
explotación observada
noninguna fuente lo reporta
SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyuan.db. Attackers can craft malicious .sy documents with non-read-only SQL statements that execute automatically during background indexing, rendering, or export operations without authentication.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Productos afectados
siyuan-note · siyuanCVEs relacionadas — siyuan-note siyuan
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-33476HIGHSiYuan has an Unauthenticated Arbitrary File Read via Path TraversalEPSS 3.1%CVE-2026-54066HIGHSiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read)EPSS 2.4%CVE-2026-69084CRITICALSiYuan before v3.7.3 SQL Injection via searchEmbedBlockEPSS 1.6%CVE-2026-69085CRITICALSiYuan before v3.7.3 SQL Injection via searchDocsEPSS 1.5%CVE-2026-34453HIGHSiYuan: Broken access control in /api/bookmark/getBookmark allows unauthenticated publish visitors to read password-protected bookmarked contentEPSS 1.5%CVE-2026-30869CRITICALSiYuan has a Path Traversal in /export Endpoint Allows Arbitrary File Read and Secret LeakageEPSS 1.2%