CVE@CVEnewDisclosure
The text announces an authorization bypass vulnerability in SiYuan 3.6.0 and earlier, affecting the /api/search/fullTextSearchBlock endpoint.
CVEFind.com@CveFindComDisclosure
The post announces a critical authorization bypass flaw in SiYuan versions 3.6.0 and earlier, enabling authenticated users to run unauthorized SQL via the /api/search/fullTextSearchBlock endpoint.
0day Signal@0dayPublishingDisclosure
A brief alert announcing an authorization bypass vulnerability (CVE-2026-32767) in SiYuan, highlighting that a simple API query allows full database access, but no PoC, exploit, active exploitation, or patch information is provided.
PulsePatch.io@pulsepatchioDisclosure
The post announces an auth bypass in SiYuan that allows arbitrary SQL execution via its search API, urging administrators to review deployments, but provides no evidence of exploitation, exploits, patches, or PoC details.