<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 05:39:08 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352761</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352761</link>
      <description>EUVD-2026-352761</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352761</guid>
    </item>
    <item>
      <title>fkie_cve-2026-72807</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-72807</link>
      <description>&lt;p&gt;SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template columns that expose the queryBlocks function, which executes raw SQL using string substitution instead of parameterized queries. Attackers can distribute malicious SiYuan documents or packages with crafted template columns that execute arbitrary SQL on a victim&amp;#39;s kernel when the package is imported and rendered, enabling read and write access across notebooks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template columns that expose the queryBlocks function, which executes raw SQL using string substitution instead of parameterized queries. Attackers can distribute malicious SiYuan documents or packages with crafted template columns that execute arbitrary SQL on a victim&amp;#39;s kernel when the package is imported and rendered, enabling read and write access across notebooks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-72807</guid>
    </item>
    <item>
      <title>GHSA-x67c-8pwr-m8g3 — SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x67c-8pwr-m8g3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;**CVE:** This vulnerability corresponds to [CVE-2026-72807](https://nvd.nist.gov/vuln/detail/CVE-2026-72807).&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Attribute-view (AV) template columns are live-evaluated on every render and expose the `queryBlocks` template function, which runs raw SQL on the read-write database handle (`SelectBlocksRawStmt`, using `?`→argument string substitution rather than parameter binding). AV mutations are admin-gated, so this is not directly reader-injectable but it is a second-order vector: an attacker distributes a SiYuan document or AV package whose template column contains `.action{queryBlocks &amp;#34;&amp;lt;arbitrary SQL&amp;gt;&amp;#34;}` when a victim imports the package and renders the AV, the attacker&amp;#39;s SQL executes on the victim&amp;#39;s kernel (read and, via statement stacking, write).&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Doc-level `{{…}}` templates are rendered at insert-time and become static, so they are not re-evaluated on reader view. The residual is AV template columns, which are live-evaluated at render. `queryBlocks` passes its argument to `SelectBlocksRawStmt` with `?`→arg string substitution, not a bound parameter, on the main read-write handle (`88250/go-sqlite3` fork, statement-stacking capable) so an attacker-controlled template argument becomes arbitrary SQL.&lt;/p&gt;
&lt;p&gt;The SSTI surface is otherwise hardened: `BuiltInTemplateFuncs` deletes `env`, `expandenv`, and `getHostByName` so there is no environment/host/file/exec SSTI. `queryBlocks`-to-SQL is the remaining live-evaluated sink.&lt;/p&gt;
&lt;p&gt;### Proof of Concept&lt;/p&gt;
&lt;p&gt;An AV temp…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;**CVE:** This vulnerability corresponds to [CVE-2026-72807](https://nvd.nist.gov/vuln/detail/CVE-2026-72807).&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Attribute-view (AV) template columns are live-evaluated on every render and expose the `queryBlocks` template function, which runs raw SQL on the read-write database handle (`SelectBlocksRawStmt`, using `?`→argument string substitution rather than parameter binding). AV mutations are admin-gated, so this is not directly reader-injectable but it is a second-order vector: an attacker distributes a SiYuan document or AV package whose template column contains `.action{queryBlocks &amp;#34;&amp;lt;arbitrary SQL&amp;gt;&amp;#34;}` when a victim imports the package and renders the AV, the attacker&amp;#39;s SQL executes on the victim&amp;#39;s kernel (read and, via statement stacking, write).&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Doc-level `{{…}}` templates are rendered at insert-time and become static, so they are not re-evaluated on reader view. The residual is AV template columns, which are live-evaluated at render. `queryBlocks` passes its argument to `SelectBlocksRawStmt` with `?`→arg string substitution, not a bound parameter, on the main read-write handle (`88250/go-sqlite3` fork, statement-stacking capable) so an attacker-controlled template argument becomes arbitrary SQL.&lt;/p&gt;
&lt;p&gt;The SSTI surface is otherwise hardened: `BuiltInTemplateFuncs` deletes `env`, `expandenv`, and `getHostByName` so there is no environment/host/file/exec SSTI. `queryBlocks`-to-SQL is the remaining live-evaluated sink.&lt;/p&gt;
&lt;p&gt;### Proof of Concept&lt;/p&gt;
&lt;p&gt;An AV temp…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x67c-8pwr-m8g3</guid>
    </item>
  </channel>
</rss>
