CVE-2026-87808
Deferred Deferred - Pending Action

SiYuan Read-Only Bypass via SQL Injection

Vulnerability report for CVE-2026-87808, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: VulnCheck

Description

SiYuan versions <= 3.8.1 contain an incomplete fix for CVE-2026-32767 (GHSA-j7wh-x834-p3r7). The prior fix (commit d5e2d0bc) added an administrator check for SQL mode (method=2) in POST /api/search/fullTextSearchBlock, but the endpoint still does not enforce the application's read-only boundary: for method=2 it forwards caller-supplied SQL to the blocks database query path without calling model.CheckReadonly or CheckReadonlyStatementInBox. As a result, when a workspace runs in read-only mode (--readonly=true), an authenticated administrator can submit arbitrary SQL through /api/search/fullTextSearchBlock and obtain raw read access to the blocks database, even though the dedicated /api/query/sql endpoint is blocked in that mode. Fixed in v3.8.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
siyuan siyuan to 3.8.2 (exc)
siyuan siyuan 3.8.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-693 The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-87808 is a residual security flaw in SiYuan versions 3.8.1 and earlier. It involves the /api/search/fullTextSearchBlock endpoint, which was partially fixed for a prior vulnerability (CVE-2026-32767) but still allows authenticated administrators to bypass read-only mode restrictions. The endpoint accepts SQL queries via method=2 and executes them against the blocks database without enforcing read-only checks like CheckReadonly or CheckReadonlyStatementInBox. This enables raw read access to sensitive data even when the workspace is in read-only mode.

Detection Guidance

To detect this vulnerability, check if your SiYuan instance is running version 3.8.1 or earlier. Inspect network traffic for POST requests to /api/search/fullTextSearchBlock with method=2 from admin accounts. Monitor database queries for unauthorized access patterns.

Impact Analysis

If you use SiYuan in read-only mode (--readonly=true), an attacker with administrator privileges could exploit this flaw to read sensitive data from the blocks database. This bypasses the intended read-only restrictions and allows unauthorized access to confidential information stored in the application.

Compliance Impact

This vulnerability could lead to unauthorized data access, violating compliance requirements for data protection standards like GDPR and HIPAA. Exposure of sensitive information may result in legal penalties, reputational damage, and failure to meet regulatory obligations for data confidentiality and integrity.

Mitigation Strategies

Upgrade SiYuan to version 3.8.2 or later immediately. Disable admin privileges for non-essential accounts. Block or monitor POST requests to /api/search/fullTextSearchBlock with method=2 in read-only mode. Review database access logs for suspicious queries.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87808. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart