CVE-2026-87807: siyuan before v3.8.2 SQL Injection via fullTextSearchBlock

Published Sep 9, 2026
·
Updated

siyuan versions before v3.8.2 contain an authenticated SQL injection vulnerability in the fullTextSearchBlock endpoint's method=1 query parameter. Attackers can inject UNION SELECT statements to read the entire blocks table, bypassing publish-access controls and exposing all document content and sensitive attributes.

Affected Software

1 affected component
SiYuan<3.8.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade siyuan to a version that resolves this vulnerability.

    Fixed in v3.8.2
  2. Compensating control

    Temporarily restrict network access (e.g., via firewall/WAF/ACL) to the fullTextSearchBlock endpoint method=1 until upgrading to v3.8.2.

Event History

Sep 9, 2026
CVE Published
via MITRE·11:20 AM
Data Sourced
via MITRE·11:20 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Does exploitation require an authenticated account?

Yes. The vulnerability description identifies this as an authenticated SQL injection issue, despite the listed vector showing PR:N.

2

What information could be exposed if the issue is exploited?

An attacker can use UNION SELECT injection to read the entire blocks table. This can expose all document content and sensitive attributes.

3

Are publish-access controls sufficient to protect affected content?

No. Successful exploitation bypasses publish-access controls when reading data from the blocks table.

4

Which SiYuan versions are affected?

SiYuan versions before v3.8.2 are affected. Updating to v3.8.2 or later addresses the affected version range identified in the data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203