CVE-2026-32704: SiYuan's renderSprig has a missing admin check that allows any user to read full workspace DB
(updated )
POST /api/template/renderSprig lacks model.CheckAdminRole, allowing any authenticated user to execute arbitrary SQL queries against the SiYuan workspace database and exfiltrate all note content, metadata, and custom attributes.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-32704 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →