
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32767 is an authorization bypass and SQL injection vulnerability in SiYuan, a personal knowledge management system developed by b3log. The flaw exists in the /api/search/fullTextSearchBlock endpoint, which — when the method parameter is set to 2 — passes user-supplied input directly as a raw SQL statement to the underlying SQLite database without any authorization or read-only checks. This allows any authenticated user, including those with only the Reader role, to execute arbitrary SQL statements (SELECT, DELETE, UPDATE, DROP TABLE, etc.). Versions 3.6.0 and below are affected; the issue was disclosed on March 14, 2026, and patched in version 3.6.1. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, SiYuan Advisory).
The root cause is a combination of CWE-89 (SQL Injection) and CWE-863 (Incorrect Authorization). In kernel/api/router.go, the /api/search/fullTextSearchBlock endpoint is registered with only the model.CheckAuth middleware, which permits any authenticated role (Administrator, Editor, or Reader), unlike the dedicated /api/query/sql endpoint which correctly chains CheckAdminRole and CheckReadonly middleware. When method=2 is supplied, the raw query parameter flows through model.FullTextSearchBlock() → searchBySQL() → sql.SelectBlocksRawStmt() → Go's database/sql db.Query(), which executes any SQL statement without restriction. Notably, if the SQL parser fails to parse the statement, the code falls through to selectBlocksRawStmt() which executes the raw statement directly, meaning even malformed SQL may trigger execution. The fix, applied in commit d5e2d0b, adds an explicit role check in kernel/api/search.go that rejects method=2 requests from non-administrator users (GitHub Advisory, Patch Commit).
Successful exploitation allows any authenticated user — even one with the lowest-privilege Reader role — to fully compromise the SiYuan SQLite database. Confidentiality is breached as all blocks, assets, references, and configuration data can be read; integrity is violated as data can be modified or deleted; and availability is threatened as tables can be dropped, rendering the application unusable. The impact is most severe in multi-user deployments such as Docker instances with network-accessible publish services, where Reader-role accounts may be broadly distributed (SiYuan Advisory).
A proof-of-concept exploit is publicly available in the GitHub Security Advisory, consisting of explicit curl commands with JSON payloads that trigger arbitrary SQL execution (SELECT, DELETE, DROP TABLE) against a live SiYuan instance (SiYuan Advisory). The only prerequisite is a valid authentication token for any user role, including Reader. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.047% (0.000470), indicating a currently low probability of active exploitation (GitHub Advisory). This CVE is not listed in the CISA KEV catalog.
/api/search/fullTextSearchBlock with method set to 2 and the desired SQL statement in the query field.curl -X POST http://<target>:6806/api/search/fullTextSearchBlock \
-H "Content-Type: application/json" \
-H "Authorization: Token <reader_token>" \
-d '{"method": 2, "query": "SELECT * FROM blocks LIMIT 100"}'curl -X POST http://<target>:6806/api/search/fullTextSearchBlock \
-H "Content-Type: application/json" \
-H "Authorization: Token <reader_token>" \
-d '{"method": 2, "query": "DELETE FROM blocks"}'/api/query/sql (SiYuan Advisory)./api/search/fullTextSearchBlock on port 6806 containing JSON bodies with "method": 2 and SQL keywords (SELECT, DELETE, DROP, UPDATE) in the query field; unexpected outbound connections from the SiYuan host following such requests./api/search/fullTextSearchBlock from Reader-role accounts; HTTP 200 responses to requests containing destructive SQL statements (pre-patch)..db files in the SiYuan data directory).The primary remediation is to upgrade SiYuan to version 3.6.1 or later, which adds an explicit administrator role check for method=2 requests in the search endpoint (SiYuan v3.6.1 Release, Patch Commit). As a temporary workaround prior to patching, restrict network access to the /api/search/fullTextSearchBlock endpoint via firewall rules or reverse proxy ACLs, and limit SiYuan exposure to trusted networks only. Administrators should also audit the SQLite database for unauthorized modifications (deleted records, dropped tables) that may have occurred before patching (GitHub Advisory).
The vulnerability was reported by researcher iconnnjka and disclosed by the SiYuan maintainer (88250) on March 14, 2026, alongside fixes for nine other security issues tracked in GitHub issue #17209. The fix was released promptly in version 3.6.1 on March 17, 2026. No significant broader media coverage or notable public researcher commentary beyond the advisory itself has been identified (SiYuan Advisory, GitHub Issue).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."