GHSA-2jmx-q9jf-wp3w

Suggest an improvement
Source
https://github.com/advisories/GHSA-2jmx-q9jf-wp3w
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-2jmx-q9jf-wp3w/GHSA-2jmx-q9jf-wp3w.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-2jmx-q9jf-wp3w
Withdrawn
2026-09-03T22:49:12Z
Published
2026-08-12T21:31:42Z
Modified
2026-09-03T23:01:07Z
Severity
  • 8.0 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N CVSS Calculator
  • 8.8 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
Duplicate Advisory: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-x67c-8pwr-m8g3. This link is maintained to preserve external references.

Original Description

SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template columns that expose the queryBlocks function, which executes raw SQL using string substitution instead of parameterized queries. Attackers can distribute malicious SiYuan documents or packages with crafted template columns that execute arbitrary SQL on a victim's kernel when the package is imported and rendered, enabling read and write access across notebooks.

Database specific
{
    "cwe_ids": [
        "CWE-89"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-03T22:49:12Z",
    "nvd_published_at": "2026-08-12T20:17:52Z",
    "severity": "HIGH"
}
References

Affected packages

Go / github.com/siyuan-note/siyuan/kernel

Package

Name
github.com/siyuan-note/siyuan/kernel
View open source insights on deps.dev
Purl
pkg:golang/github.com/siyuan-note/siyuan/kernel

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Database specific

last_known_affected_version_range
"< 3.7.4"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-2jmx-q9jf-wp3w/GHSA-2jmx-q9jf-wp3w.json"