CVE-2026-29073: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-29073 is a missing authorization and SQL injection vulnerability in SiYuan, a personal knowledge management system developed by b3log. The /api/query/sql endpoint allows any authenticated user — including those with only reader-level privileges — to execute arbitrary SQL queries directly against the application's database, bypassing admin-only access controls. All versions up to and including 3.5.9 (advisory references ≤ 3.5.3) are affected; the issue was patched in version 3.6.0. It was published on March 6, 2026, with a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is a combination of CWE-862 (Missing Authorization) and CWE-89 (SQL Injection). The vulnerable endpoint /api/query/sql is defined in kernel/api/sql.go and registered in kernel/api/router.go using only the CheckAuth middleware, which verifies that a user is logged in but does not enforce admin-level privileges. The SQL() handler extracts the stmt parameter from the request body and passes it directly to sql.Query() without any input validation, restriction on query type (SELECT vs. write operations), or role-based access check. This means any authenticated user — including read-only accounts — can submit arbitrary SQL statements via a simple HTTP POST request (GitHub Advisory).

Impact

Any authenticated user, regardless of privilege level, can read all data stored in the SiYuan SQLite database, including notes, blocks, and content belonging to other users. Beyond data exfiltration, the lack of query-type validation means write operations (INSERT, UPDATE, DELETE) may also be possible, threatening data integrity. Malicious or resource-intensive SQL queries could also cause significant performance degradation or denial of service for the affected instance (GitHub Advisory).

Exploitability

A proof-of-concept (PoC) is publicly available in the GitHub Security Advisory, demonstrating exploitation via simple curl commands using reader-level credentials. The EPSS score is 0.043% (low automated exploitation probability), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing. The CVSSv4 exploit maturity is rated as PROOF_OF_CONCEPT (GitHub Advisory, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify a SiYuan instance with the publish/API service enabled (default port 6808), running version 3.5.9 or earlier.
  2. Obtain low-privilege credentials: Acquire any valid SiYuan account credentials, including a reader-level account.
  3. Enumerate database schema: Send a POST request to /api/query/sql with basic authentication to list all tables:
curl -s -u reader_user:reader_pass \
  -X POST "http://<target>:6808/api/query/sql" \
  -H "Content-Type: application/json" \
  -d '{"stmt": "SELECT name, type FROM sqlite_master WHERE type=\'table\'"}'
  1. Extract sensitive data: Query the blocks table or other tables to retrieve all user notes and content:
curl -s -u reader_user:reader_pass \
  -X POST "http://<target>:6808/api/query/sql" \
  -H "Content-Type: application/json" \
  -d '{"stmt": "SELECT id, content FROM blocks"}'
  1. Attempt write operations: Submit INSERT, UPDATE, or DELETE statements to modify or corrupt database content, or craft resource-intensive queries to degrade service availability (GitHub Advisory).

Indicators of compromise

  • Network: Unusual or repeated HTTP POST requests to /api/query/sql from non-admin user accounts; requests containing SQL keywords (SELECT, INSERT, UPDATE, DELETE, sqlite_master) in the request body.
  • Logs: SiYuan API access logs showing POST requests to /api/query/sql authenticated by reader-level or unexpected user accounts; high-frequency queries or queries referencing sqlite_master or sensitive tables like blocks.
  • Application Behavior: Unexpected database performance degradation or errors; data modifications (missing or altered notes/blocks) not attributable to admin actions.

Mitigation and workarounds

Upgrade SiYuan to version 3.6.0 or later, which patches this vulnerability by enforcing proper admin-level authorization checks on the /api/query/sql endpoint. As an interim workaround, restrict network access to the SiYuan API port (default 6808) using firewall rules or network segmentation to prevent unauthorized users from reaching the endpoint. Avoid exposing the SiYuan publish service to untrusted networks until the patch is applied (GitHub Advisory).

Community reactions

The vulnerability was reported by security researcher rezmoss and disclosed via GitHub's security advisory program. An openSUSE security announcement was also published referencing this CVE. No significant broader media coverage or notable researcher commentary beyond the advisory itself has been identified (GitHub Advisory, openSUSE Announce).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management