<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T15:25:58.326244+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352694</id>
    <title>EUVD-2026-352694</title>
    <updated>2026-10-05T15:25:58.384042+00:00</updated>
    <content>EUVD-2026-352694</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352694"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-69085</id>
    <title>fkie_cve-2026-69085</title>
    <updated>2026-10-05T15:25:58.384083+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly into SQL statements with no escaping or parameter binding. The endpoint is reachable by a publish RoleReader token, or unauthenticated when publish mode is enabled with Publish.Auth.Enable set to false. Because the statement executes on a read-write SQLite handle via a driver that supports stacked (semicolon-separated) statements, an attacker can read and modify database content across all cleartext (non-encrypted) notebooks on the instance.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-69085"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-33jq-p8c2-q3q4</id>
    <title>GHSA-33jq-p8c2-q3q4 — SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write wit…</title>
    <updated>2026-10-05T15:25:58.384120+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/siyuan-note/siyuan/kernel</p>
<p>### Summary</p>
<p>The `/api/filetree/searchDocs` endpoint concatenates the caller-supplied search keyword directly into a SQL statement with no escaping and no parameter binding. The endpoint is gated by `CheckAuth` only reachable by the publish RoleReader token, and by the anonymous account when `Publish.Auth.Enable` is `false`. The resulting statement runs on a read-write SQLite handle through a driver that executes stacked (`;`-separated) statements, against the global `blocks` table spanning all cleartext notebooks. An unauthenticated request can therefore read and write database content across every non-encrypted notebook on the instance.</p>
<p>### Details</p>
<p>Data flow, unescaped and unbound at every hop:</p>
<p>- `searchDocs` (`kernel/api/filetree.go`): `k := arg["k"].(string)` passed straight to `model.SearchDocs(k, …)`, no sanitization.
- `SearchDocs` (`kernel/model/file.go`): after `TrimSpace` and `strings.Fields`, each token is spliced into a single-quoted `LIKE` literal by concatenation `condition.WriteString("(hpath LIKE '%" + k + "%'")`. No escaping, no `''` doubling, no bind placeholder.
- `NAMFilter` (`kernel/conf/search.go`): appends `" OR name LIKE '%" + keyword + "%'"` (and `alias`, `memo`) the same way, enabled by default.
- `QueryRootBlockByCondition` (`kernel/sql/block_query.go`): `"SELECT *, … FROM blocks WHERE type = 'd' AND " + condition + " ORDER BY … LIMIT …"` passed to `query(sqlStmt)`.</p>
<p>The only value-inspecting guard is `ast.IsNodeIDPattern(keyword)`, which merely…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-33jq-p8c2-q3q4"/>
  </entry>
</feed>
