Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-55660

SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's `/api/template/renderSprig` endpoint is vulnerable to Server-Side Template Injection (SSTI) through the Sprig template engine. Although the engine has limitations, it allows attackers to access environment variables. Version 3.1.16 contains a patch for the issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 32.9%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2024-55660
  • B3log » Siyuan » Version: 3.1.15
    cpe:2.3:a:b3log:siyuan:3.1.15


Contact Us

Shodan ® - All rights reserved