SiYuan has an SSTI via /api/template/renderSprig
Moderate severity
GitHub Reviewed
Published
Dec 11, 2024
in
siyuan-note/siyuan
•
Updated Dec 12, 2024
Package
Affected versions
<= 0.0.0-20241210012039-5129ad926a21
Patched versions
None
Description
Published to the GitHub Advisory Database
Dec 11, 2024
Reviewed
Dec 11, 2024
Published by the National Vulnerability Database
Dec 12, 2024
Last updated
Dec 12, 2024
Summary
Siyuan's /api/template/renderSprig endpoint is vulnerable to Server-Side Template Injection (SSTI) through the Sprig template engine. Although the engine has limitations, it allows attackers to access environment variables
Impact
Information leakage
References