CVE-2024-55660: SiYuan has an SSTI via /api/template/renderSprig
Summary Siyuan's /api/template/renderSprig endpoint is vulnerable to Server-Side Template Injection (SSTI) through the Sprig template engine. Although the engine has limitations, it allows attackers to access environment variables
Impact
Information leakage
Other sources
SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's /api/template/renderSprig endpoint is vulnerable to Server-Side Template Injection (SSTI) through the Sprig template engine. Although the engine has limitations, it allows attackers to access environment variables. Version 3.1.16 contains a patch for the issue.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-55660?
CVE-2024-55660 is classified as a high-severity vulnerability due to the potential for information leakage.
How does CVE-2024-55660 allow exploitation?
CVE-2024-55660 allows exploitation through Server-Side Template Injection via the vulnerable /api/template/renderSprig endpoint.
What systems are affected by CVE-2024-55660?
CVE-2024-55660 affects Siyuan versions up to and including 0.0.0-20241210012039-5129ad926a21.
How do I fix CVE-2024-55660?
To fix CVE-2024-55660, update to a version of Siyuan that is not affected by the vulnerability.
What impact does CVE-2024-55660 have on user data?
CVE-2024-55660 can lead to the exposure of sensitive environment variables, posing a risk to user data.