SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB in github.com/siyuan-note/siyuan/kernel
{
"review_status": "UNREVIEWED",
"url": "https://pkg.go.dev/vuln/GO-2026-6374"
}