
CVE-2026-29073 (CVSS:5.7, HIGH) is Analyzed. SiYuan is a personal knowledge management system. Prior to version 3.6.0, the /api/query/sql lets a user run sql directl..https://nvd.nist.gov/vuln/detail/CVE-2026-29073 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
Post summary
The post describes a SQL injection flaw in SiYuan’s /api/query/sql endpoint (CVE-2026-29073) that permits arbitrary SQL execution on versions prior to 3.6.0; no PoC, exploit, or patch details are provided.



