CVE-2026-101091: SiYuan before v3.8.4 SQL Injection via Block Query Embed
SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyuan.db. Attackers can craft malicious .sy documents with non-read-only SQL statements that execute automatically during background indexing, rendering, or export operations without authentication.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiYuanto a version that resolves this vulnerability.Fixed in 3.8.4
Event History
Frequently Asked Questions
Which installations are affected?
SiYuan versions before v3.8.4 are affected. Check the installed SiYuan version to determine whether the instance falls within the vulnerable range.
What does an attacker need to exploit this issue?
An attacker needs to craft a malicious .sy document containing a block query embed with a non-read-only SQL statement. The SQL can execute without authentication.
When can the malicious SQL execute?
Execution can occur automatically when the malicious document is processed during background indexing, rendering, or export operations.
What is the available remediation?
Upgrade SiYuan to v3.8.4 or later, since versions before v3.8.4 are affected.