FlawAtlas
Search the atlas
CVE-2024-55660 Moderate

SiYuan has an SSTI via /api/template/renderSprig in github.com/siyuan-note/siyuan/kernel

SiYuan has an SSTI via /api/template/renderSprig in github.com/siyuan-note/siyuan/kernel

Exploit probability 0.6%
Published December 12, 2024
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

2 explicit affected versions

Go github.com/siyuan-note/siyuan/kernel
Go github.com/siyuan-note/siyuan/kernel

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2024-55660

SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's `/api/template/renderSprig` endpoint is vulnerable to Server-Side Template Injection (SSTI) through the Sprig template engine. Although the engine has limitations, it allows attackers to access environment variables. Version 3.1.16 contains a patch for the issue.

View original source
Open Source Vulnerabilities GO-2024-3324

SiYuan has an SSTI via /api/template/renderSprig in github.com/siyuan-note/siyuan/kernel

View original source
Open Source Vulnerabilities GHSA-4pjc-pwgq-q9jp

### Summary Siyuan's /api/template/renderSprig endpoint is vulnerable to Server-Side Template Injection (SSTI) through the Sprig template engine. Although the engine has limitations, it allows attackers to access environment variables ### Impact Information leakage

View original source

05 / REFERENCES

Further evidence