<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 11:53:16 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-276200</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-276200</link>
      <description>EUVD-2026-276200</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-276200</guid>
    </item>
    <item>
      <title>fkie_cve-2026-32704</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32704</link>
      <description>&lt;p&gt;SiYuan is a personal knowledge management system. Prior to 3.6.1, POST /api/template/renderSprig lacks model.CheckAdminRole, allowing any authenticated user to execute arbitrary SQL queries against the SiYuan workspace database and exfiltrate all note content, metadata, and custom attributes. This vulnerability is fixed in 3.6.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SiYuan is a personal knowledge management system. Prior to 3.6.1, POST /api/template/renderSprig lacks model.CheckAdminRole, allowing any authenticated user to execute arbitrary SQL queries against the SiYuan workspace database and exfiltrate all note content, metadata, and custom attributes. This vulnerability is fixed in 3.6.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-32704</guid>
    </item>
    <item>
      <title>GHSA-4j3x-hhg2-fm2x — SiYuan's renderSprig has a missing admin check that allows any user to read full workspace DB</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4j3x-hhg2-fm2x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;### Summary
`POST /api/template/renderSprig` lacks `model.CheckAdminRole`, allowing any authenticated user to execute arbitrary SQL queries against the SiYuan workspace database and exfiltrate all note content, metadata, and custom attributes.&lt;/p&gt;
&lt;p&gt;### Details
**File:** `kernel/api/router.go`&lt;/p&gt;
&lt;p&gt;Every sensitive endpoint in the codebase uses `model.CheckAuth + model.CheckAdminRole`, but `renderSprig` only has `CheckAuth`:&lt;/p&gt;
&lt;p&gt;```go
//  Missing CheckAdminRole
ginServer.Handle(&amp;#34;POST&amp;#34;, &amp;#34;/api/template/renderSprig&amp;#34;,
    model.CheckAuth, renderSprig)&lt;/p&gt;
&lt;p&gt;//  Correct pattern used by all other data endpoints
ginServer.Handle(&amp;#34;POST&amp;#34;, &amp;#34;/api/template/render&amp;#34;,
    model.CheckAuth, model.CheckAdminRole, model.CheckReadonly, renderTemplate)
```&lt;/p&gt;
&lt;p&gt;`renderSprig` calls `model.RenderGoTemplate` (`kernel/model/template.go`) which registers SQL functions from `kernel/sql/database.go`:&lt;/p&gt;
&lt;p&gt;```go
(*templateFuncMap)[&amp;#34;querySQL&amp;#34;] = func(stmt string) (ret []map[string]interface{}) {
    ret, _ = Query(stmt, 1024)  // executes raw SELECT, no role check
    return
}
```&lt;/p&gt;
&lt;p&gt;Any authenticated user - including Publish Service **Reader** role accounts - can call this endpoint and execute arbitrary SELECT queries.&lt;/p&gt;
&lt;p&gt;### PoC
**Environment:**
```bash
docker run -d --name siyuan -p 6806:6806 \
  -v $(pwd)/workspace:/siyuan/workspace \
  b3log/siyuan --workspace=/siyuan/workspace --accessAuthCode=test123
```&lt;/p&gt;
&lt;p&gt;**Exploit:**
```bash
# Step 1: Login and retrieve API token
curl -s -X POST http://localhost:6806/api/system/loginAuth \…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;### Summary
`POST /api/template/renderSprig` lacks `model.CheckAdminRole`, allowing any authenticated user to execute arbitrary SQL queries against the SiYuan workspace database and exfiltrate all note content, metadata, and custom attributes.&lt;/p&gt;
&lt;p&gt;### Details
**File:** `kernel/api/router.go`&lt;/p&gt;
&lt;p&gt;Every sensitive endpoint in the codebase uses `model.CheckAuth + model.CheckAdminRole`, but `renderSprig` only has `CheckAuth`:&lt;/p&gt;
&lt;p&gt;```go
//  Missing CheckAdminRole
ginServer.Handle(&amp;#34;POST&amp;#34;, &amp;#34;/api/template/renderSprig&amp;#34;,
    model.CheckAuth, renderSprig)&lt;/p&gt;
&lt;p&gt;//  Correct pattern used by all other data endpoints
ginServer.Handle(&amp;#34;POST&amp;#34;, &amp;#34;/api/template/render&amp;#34;,
    model.CheckAuth, model.CheckAdminRole, model.CheckReadonly, renderTemplate)
```&lt;/p&gt;
&lt;p&gt;`renderSprig` calls `model.RenderGoTemplate` (`kernel/model/template.go`) which registers SQL functions from `kernel/sql/database.go`:&lt;/p&gt;
&lt;p&gt;```go
(*templateFuncMap)[&amp;#34;querySQL&amp;#34;] = func(stmt string) (ret []map[string]interface{}) {
    ret, _ = Query(stmt, 1024)  // executes raw SELECT, no role check
    return
}
```&lt;/p&gt;
&lt;p&gt;Any authenticated user - including Publish Service **Reader** role accounts - can call this endpoint and execute arbitrary SELECT queries.&lt;/p&gt;
&lt;p&gt;### PoC
**Environment:**
```bash
docker run -d --name siyuan -p 6806:6806 \
  -v $(pwd)/workspace:/siyuan/workspace \
  b3log/siyuan --workspace=/siyuan/workspace --accessAuthCode=test123
```&lt;/p&gt;
&lt;p&gt;**Exploit:**
```bash
# Step 1: Login and retrieve API token
curl -s -X POST http://localhost:6806/api/system/loginAuth \…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4j3x-hhg2-fm2x</guid>
    </item>
  </channel>
</rss>
