Impact
The vulnerability is a server‐side template injection in the attribute‑view template calculation feature of Siyuan up to version 3.7.3. It allows a local, unauthenticated user to supply a malicious template that is evaluated by Sprig’s default function map, exposing functions such as env, expandenv, and getHostByName. By exploiting this flaw, the attacker can read environment variables from the Siyuan process account, potentially including sensitive data from other unprivileged OS accounts, and can trigger DNS queries from the server’s network location.
Affected Systems
Affected products are Siyuan 3.7.3 and earlier. Versions from 3.7.0‑beta.1 up to but not including 3.7.4 are vulnerable; the issue was resolved in 3.7.4. Systems running these releases on a host that exposes the Siyuan server to local users or to any network interface are at risk.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, and the vulnerability is not currently listed in CISA’s KEV catalog. Without an EPSS score, the probability of exploitation cannot be quantified, but the flaw requires local, unauthenticated access to the host and exploits a feature that is bound to 127.0.0.1 by default. An attacker with local machine access could extract configuration data and perform covert network queries from the server, potentially aiding further attacks.
OpenCVE Enrichment