Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 Go

SiYuan has an arbitrary file read via /api/template/render

GHSA-xx68-37v4-4596 · CVE-2024-55657 · GO-2024-3327

Published · Modified

Description

Summary

An arbitrary file read vulnerability exists in Siyuan's /api/template/render endpoint. The absence of proper validation on the path parameter allows attackers to access sensitive files on the host system.

Impact

Arbitrary file read on the host

Ready to move

Start Securing

Free, no credit card | First findings in minutes