CVE-2026-32767: Siyuan Fulltextsearchblock Missing Admin Checkcve-2026-32767-siyuan-fulltextsearchblock-missing-admin-check
Call to model.FullTextSearchBlock() inside a gin.Context handler without an `if method == 2 && !model.IsAdminRoleContext(c)` admin gate. When the `method` parameter is 2, FullTextSearchBlock forwards the user-supplied query string to searchBySQL → db.Query(), executing arbitrary SQL against the SQLite database. Without an admin role check, any authenticated