← Zuruck zu CVEs
CVE-2026-32704
MEDIUM6.5
Beschreibung
SiYuan is a personal knowledge management system. Prior to 3.6.1, POST /api/template/renderSprig lacks model.CheckAdminRole, allowing any authenticated user to execute arbitrary SQL queries against the SiYuan workspace database and exfiltrate all note content, metadata, and custom attributes. This vulnerability is fixed in 3.6.1.
CVE Details
CVSS v3.1 Bewertung6.5
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienLOW
BenutzerinteraktionNONE
Veroffentlicht3/16/2026
Zuletzt geandert3/17/2026
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
b3log:siyuan
Schwachen (CWE)
CWE-285CWE-732
Referenzen
https://github.com/siyuan-note/siyuan/security/advisories/GHSA-4j3x-hhg2-fm2x(security-advisories@github.com)
https://github.com/siyuan-note/siyuan/security/advisories/GHSA-4j3x-hhg2-fm2x(134c704f-9b21-4f2e-91b3-4a467353bcc0)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.