CVE-2026-54068

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the /api/icon/getDynamicIcon endpoint is explicitly excluded from authentication in SiYuan's kernel router (router.go, "不需要鉴权" -- no auth needed). When called with type=8 and a valid block id parameter, this endpoint invokes RenderDynamicIconContentTemplate, which executes a Go template that includes the querySQL and queryBlocks functions. These functions run arbitrary SELECT statements against the SiYuan SQLite database. An unauthenticated network-adjacent attacker who knows a valid block ID can exfiltrate all user note content, tags, asset references, and block attributes from the database. This vulnerability is fixed in 3.7.0.
Configurations

No configuration.

History

25 Jun 2026, 14:16

Type Values Removed Values Added
References () https://github.com/siyuan-note/siyuan/security/advisories/GHSA-gcm7-57gf-953c - () https://github.com/siyuan-note/siyuan/security/advisories/GHSA-gcm7-57gf-953c -

24 Jun 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-24 22:16

Updated : 2026-06-25 14:16


NVD link : CVE-2026-54068

Mitre link : CVE-2026-54068

CVE.ORG link : CVE-2026-54068


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function