SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the /api/icon/getDynamicIcon endpoint is explicitly excluded from authentication in SiYuan's kernel router (router.go, "不需要鉴权" -- no auth needed). When called with type=8 and a valid block id parameter, this endpoint invokes RenderDynamicIconContentTemplate, which executes a Go template that includes the querySQL and queryBlocks functions. These functions run arbitrary SELECT statements against the SiYuan SQLite database. An unauthenticated network-adjacent attacker who knows a valid block ID can exfiltrate all user note content, tags, asset references, and block attributes from the database. This vulnerability is fixed in 3.7.0.
References
Configurations
No configuration.
History
25 Jun 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/siyuan-note/siyuan/security/advisories/GHSA-gcm7-57gf-953c - |
24 Jun 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-24 22:16
Updated : 2026-06-25 14:16
NVD link : CVE-2026-54068
Mitre link : CVE-2026-54068
CVE.ORG link : CVE-2026-54068
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
