<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 15:50:02 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352694</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352694</link>
      <description>EUVD-2026-352694</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352694</guid>
    </item>
    <item>
      <title>fkie_cve-2026-69085</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-69085</link>
      <description>&lt;p&gt;SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly into SQL statements with no escaping or parameter binding. The endpoint is reachable by a publish RoleReader token, or unauthenticated when publish mode is enabled with Publish.Auth.Enable set to false. Because the statement executes on a read-write SQLite handle via a driver that supports stacked (semicolon-separated) statements, an attacker can read and modify database content across all cleartext (non-encrypted) notebooks on the instance.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly into SQL statements with no escaping or parameter binding. The endpoint is reachable by a publish RoleReader token, or unauthenticated when publish mode is enabled with Publish.Auth.Enable set to false. Because the statement executes on a read-write SQLite handle via a driver that supports stacked (semicolon-separated) statements, an attacker can read and modify database content across all cleartext (non-encrypted) notebooks on the instance.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-69085</guid>
    </item>
    <item>
      <title>GHSA-33jq-p8c2-q3q4 — SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write wit…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-33jq-p8c2-q3q4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `/api/filetree/searchDocs` endpoint concatenates the caller-supplied search keyword directly into a SQL statement with no escaping and no parameter binding. The endpoint is gated by `CheckAuth` only reachable by the publish RoleReader token, and by the anonymous account when `Publish.Auth.Enable` is `false`. The resulting statement runs on a read-write SQLite handle through a driver that executes stacked (`;`-separated) statements, against the global `blocks` table spanning all cleartext notebooks. An unauthenticated request can therefore read and write database content across every non-encrypted notebook on the instance.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Data flow, unescaped and unbound at every hop:&lt;/p&gt;
&lt;p&gt;- `searchDocs` (`kernel/api/filetree.go`): `k := arg[&amp;#34;k&amp;#34;].(string)` passed straight to `model.SearchDocs(k, …)`, no sanitization.
- `SearchDocs` (`kernel/model/file.go`): after `TrimSpace` and `strings.Fields`, each token is spliced into a single-quoted `LIKE` literal by concatenation `condition.WriteString(&amp;#34;(hpath LIKE &amp;#39;%&amp;#34; + k + &amp;#34;%&amp;#39;&amp;#34;)`. No escaping, no `&amp;#39;&amp;#39;` doubling, no bind placeholder.
- `NAMFilter` (`kernel/conf/search.go`): appends `&amp;#34; OR name LIKE &amp;#39;%&amp;#34; + keyword + &amp;#34;%&amp;#39;&amp;#34;` (and `alias`, `memo`) the same way, enabled by default.
- `QueryRootBlockByCondition` (`kernel/sql/block_query.go`): `&amp;#34;SELECT *, … FROM blocks WHERE type = &amp;#39;d&amp;#39; AND &amp;#34; + condition + &amp;#34; ORDER BY … LIMIT …&amp;#34;` passed to `query(sqlStmt)`.&lt;/p&gt;
&lt;p&gt;The only value-inspecting guard is `ast.IsNodeIDPattern(keyword)`, which merely…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `/api/filetree/searchDocs` endpoint concatenates the caller-supplied search keyword directly into a SQL statement with no escaping and no parameter binding. The endpoint is gated by `CheckAuth` only reachable by the publish RoleReader token, and by the anonymous account when `Publish.Auth.Enable` is `false`. The resulting statement runs on a read-write SQLite handle through a driver that executes stacked (`;`-separated) statements, against the global `blocks` table spanning all cleartext notebooks. An unauthenticated request can therefore read and write database content across every non-encrypted notebook on the instance.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Data flow, unescaped and unbound at every hop:&lt;/p&gt;
&lt;p&gt;- `searchDocs` (`kernel/api/filetree.go`): `k := arg[&amp;#34;k&amp;#34;].(string)` passed straight to `model.SearchDocs(k, …)`, no sanitization.
- `SearchDocs` (`kernel/model/file.go`): after `TrimSpace` and `strings.Fields`, each token is spliced into a single-quoted `LIKE` literal by concatenation `condition.WriteString(&amp;#34;(hpath LIKE &amp;#39;%&amp;#34; + k + &amp;#34;%&amp;#39;&amp;#34;)`. No escaping, no `&amp;#39;&amp;#39;` doubling, no bind placeholder.
- `NAMFilter` (`kernel/conf/search.go`): appends `&amp;#34; OR name LIKE &amp;#39;%&amp;#34; + keyword + &amp;#34;%&amp;#39;&amp;#34;` (and `alias`, `memo`) the same way, enabled by default.
- `QueryRootBlockByCondition` (`kernel/sql/block_query.go`): `&amp;#34;SELECT *, … FROM blocks WHERE type = &amp;#39;d&amp;#39; AND &amp;#34; + condition + &amp;#34; ORDER BY … LIMIT …&amp;#34;` passed to `query(sqlStmt)`.&lt;/p&gt;
&lt;p&gt;The only value-inspecting guard is `ast.IsNodeIDPattern(keyword)`, which merely…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-33jq-p8c2-q3q4</guid>
    </item>
  </channel>
</rss>
