
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-29073 is a missing authorization and SQL injection vulnerability in SiYuan, a personal knowledge management system developed by b3log. The /api/query/sql endpoint allows any authenticated user — including those with only reader-level privileges — to execute arbitrary SQL queries directly against the application's database, bypassing admin-only access controls. All versions up to and including 3.5.9 (advisory references ≤ 3.5.3) are affected; the issue was patched in version 3.6.0. It was published on March 6, 2026, with a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Red Hat CVE).
The root cause is a combination of CWE-862 (Missing Authorization) and CWE-89 (SQL Injection). The vulnerable endpoint /api/query/sql is defined in kernel/api/sql.go and registered in kernel/api/router.go using only the CheckAuth middleware, which verifies that a user is logged in but does not enforce admin-level privileges. The SQL() handler extracts the stmt parameter from the request body and passes it directly to sql.Query() without any input validation, restriction on query type (SELECT vs. write operations), or role-based access check. This means any authenticated user — including read-only accounts — can submit arbitrary SQL statements via a simple HTTP POST request (GitHub Advisory).
Any authenticated user, regardless of privilege level, can read all data stored in the SiYuan SQLite database, including notes, blocks, and content belonging to other users. Beyond data exfiltration, the lack of query-type validation means write operations (INSERT, UPDATE, DELETE) may also be possible, threatening data integrity. Malicious or resource-intensive SQL queries could also cause significant performance degradation or denial of service for the affected instance (GitHub Advisory).
A proof-of-concept (PoC) is publicly available in the GitHub Security Advisory, demonstrating exploitation via simple curl commands using reader-level credentials. The EPSS score is 0.043% (low automated exploitation probability), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing. The CVSSv4 exploit maturity is rated as PROOF_OF_CONCEPT (GitHub Advisory, Red Hat CVE).
/api/query/sql with basic authentication to list all tables:curl -s -u reader_user:reader_pass \
-X POST "http://<target>:6808/api/query/sql" \
-H "Content-Type: application/json" \
-d '{"stmt": "SELECT name, type FROM sqlite_master WHERE type=\'table\'"}'blocks table or other tables to retrieve all user notes and content:curl -s -u reader_user:reader_pass \
-X POST "http://<target>:6808/api/query/sql" \
-H "Content-Type: application/json" \
-d '{"stmt": "SELECT id, content FROM blocks"}'/api/query/sql from non-admin user accounts; requests containing SQL keywords (SELECT, INSERT, UPDATE, DELETE, sqlite_master) in the request body./api/query/sql authenticated by reader-level or unexpected user accounts; high-frequency queries or queries referencing sqlite_master or sensitive tables like blocks.Upgrade SiYuan to version 3.6.0 or later, which patches this vulnerability by enforcing proper admin-level authorization checks on the /api/query/sql endpoint. As an interim workaround, restrict network access to the SiYuan API port (default 6808) using firewall rules or network segmentation to prevent unauthorized users from reaching the endpoint. Avoid exposing the SiYuan publish service to untrusted networks until the patch is applied (GitHub Advisory).
The vulnerability was reported by security researcher rezmoss and disclosed via GitHub's security advisory program. An openSUSE security announcement was also published referencing this CVE. No significant broader media coverage or notable researcher commentary beyond the advisory itself has been identified (GitHub Advisory, openSUSE Announce).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."