Executive brief
SiYuan is a note-taking and knowledge management application. An authenticated attacker can read sensitive workspace files—including configuration files containing API tokens and cryptographic signing keys—by submitting crafted requests to the template rendering endpoint. This could allow an attacker to gain elevated access or impersonate legitimate API calls.
Technical details
The RenderTemplate function in kernel/model/template.go reads arbitrary files via os.ReadFile() with no sensitive-path exclusion list. The endpoint restricts paths only to the workspace directory via util.IsAbsPathInWorkspace(), but unlike the file API's refuseToAccess() blocklist, it does not exclude sensitive files such as conf/conf.json. Since the configuration directory resides within the workspace, an authenticated attacker can read sensitive workspace files including API tokens and cookie signing keys. The vulnerability requires authentication and network access to the POST /api/template/render endpoint. The fix is available in v3.8.1.
Affected products
- SiYuan SiYuan 3.8.0
Timeline
- 2026-08-30: disclosed
- 2026: patched: Fixed in v3.8.1