PT-2024-36575 · Siyuan · Siyuan

Elleuch-X1

·

Published

2024-12-11

·

Updated

2024-12-18

·

CVE-2024-55660

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.1.16
Description SiYuan's /api/template/renderSprig endpoint is vulnerable to Server-Side Template Injection (SSTI) through the Sprig template engine. Although the engine has limitations, it allows attackers to access environment variables, potentially leading to information leakage.
Recommendations For versions prior to 3.1.16, update to version 3.1.16 to resolve the issue. As a temporary workaround, consider restricting access to the /api/template/renderSprig endpoint until the update is applied.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-55660
GHSA-4PJC-PWGQ-Q9JP
GO-2024-3324
OPENSUSE-SU-2024:14599-1

Affected Products

Siyuan