CVE-2026-59834General

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the block search endpoint POST /api/search/fullTextSearchBlock concatenates attacker-controlled paths values into SQL predicates used by non-SQL search modes, allowing an unauthenticated publish visitor to inject a UNION SELECT and return rows from hidden documents by projecting an allowed visible box and path. This issue is fixed in versions 3.7.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-07-10); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-07-10: 3Mentions · 2026-09-02: 1Patch / Workaround · 2026-07-10: 1Technical Details · 2026-07-10: 2Technical Details · 2026-09-02: 107-1009-02
Signal classification3 categories
General
250.0%
Disclosure
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-07-103
Disclosure1General1Patch1
2026-09-021
General1
Full discourse4 posts
  • DailyCVE@dailycve
    General

    🔴 SiYuan (siyuan-note), SQL Injection, #CVE-2026-59834 (High) -DC-Sep2026-2086 https://dailycve.com/siyuan-siyuan-note-sql-injection-cve-2026-59834-high-dc-sep2026-2086/

    Post summary

    A brief alert announcing a high‑severity SQL Injection vulnerability (CVE‑2026‑59834) in SiYuan, with no specific PoC, exploit, or mitigation details provided.

    0000035
    233 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-59834 SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the block search endpoint POST /api/search/fullTextSearchBlock concatenates attacker-co… https://www.cve.org/CVERecord?id=CVE-2026-59834 ----- Traducción: CVE-2026-59834 SiY… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑59834 in SiYuan, highlighting a flaw in the full-text search endpoint present before version 3.7.1, but it does not provide a PoC, exploit, patch, or evidence of active exploitation.

    0000044
    91 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-59834 SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the block search endpoint POST /api/search/fullTextSearchBlock concatenates attacker-co… https://www.cve.org/CVERecord?id=CVE-2026-59834

    Post summary

    The text briefly notes CVE‑2026‑59834 in SiYuan, referencing an endpoint that performs concatenation before version 3.7.1, but contains no further details about the vulnerability, exploitation, or remediation.

    00000649
    57.8K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    #CVE-2026-59834 - #SQLi in #Siyuan's block search endpoint. Unauthenticated #UNION SELECT injection exposes hidden docs. #CVSS 7.5. Update to 3.7.1 immediately. https://www.valtersit.com/cve/CVE-2026-59834/ #CVEAlert #infosec #SiYuan #devsecops #devops #developers #sysadmin #cybernews #redteam #blueteam

    Post summary

    Siyuan’s block search endpoint is vulnerable to unauthenticated SQL injection, exposing hidden documents; a CVSS score of 7.5 is assigned, and users are urged to update to version 3.7.1 immediately.

    0000066
    975 followersView on X

Explore more