Launch Week Day 1: Announcing Security Design Review
UNKNOWN Go

SiYuan has an SSTI via /api/template/renderSprig

GHSA-4pjc-pwgq-q9jp · CVE-2024-55660 · GO-2024-3324

Published · Modified

Description

Summary

Siyuan's /api/template/renderSprig endpoint is vulnerable to Server-Side Template Injection (SSTI) through the Sprig template engine. Although the engine has limitations, it allows attackers to access environment variables

Impact

Information leakage

Ready to move

Start Securing

Free, no credit card | First findings in minutes