CVE-2026-29073Disclosure(b3log / siyuan)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SiYuan is a personal knowledge management system. Prior to version 3.6.0, the /api/query/sql lets a user run sql directly, but it only checks basic auth, not admin rights, any logged-in user, even readers, can run any sql query on the database. This issue has been patched in version 3.6.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • siyuan

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-06); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
siyuan

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-06: 3Mentions · 2026-03-11: 1Technical Details · 2026-03-06: 3Technical Details · 2026-03-11: 103-0603-11
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-063
Disclosure3
2026-03-111
Disclosure1
Full discourse4 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-29073 (CVSS:5.7, HIGH) is Analyzed. SiYuan is a personal knowledge management system. Prior to version 3.6.0, the /api/query/sql lets a user run sql directl..https://nvd.nist.gov/vuln/detail/CVE-2026-29073 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post describes a SQL injection flaw in SiYuan’s /api/query/sql endpoint (CVE-2026-29073) that permits arbitrary SQL execution on versions prior to 3.6.0; no PoC, exploit, or patch details are provided.

    0000027
    172 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29073 SiYuan is a personal knowledge management system. Prior to version 3.6.0, the /api/query/sql lets a user run sql directly, but it only checks basic auth, not admin ri… https://www.cve.org/CVERecord?id=CVE-2026-29073

    Post summary

    Prior to version 3.6.0, SiYuan’s /api/query/sql endpoint allowed arbitrary SQL execution with only basic authentication, exposing the system to potential SQL injection.

    00000117
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-29073 SQL Injection in SiYuan Knowledge Management System Prior to Version 3.6.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-29073

    Post summary

    A SQL Injection vulnerability (CVE-2026-29073) in SiYuan Knowledge Management System prior to version 3.6.0 is announced, with no PoC, exploit, or patch information provided.

    0000042
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-29073 - SiYuan: Direct SQL Query API accessible to Reader-level users enables unauthorized database access Intel Report: https://ift.tt/Gw9y2EQ

    Post summary

    The tweet announces CVE-2026-29073, describing that SiYuan’s Direct SQL Query API can be abused by reader-level users to gain unauthorized database access.

    0000033
    343 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appb3logsiyuan---

Explore more