High severity8.3NVD Advisory· Published Mar 11, 2026· Updated Jun 17, 2026
CVE-2026-32110
CVE-2026-32110
Description
SiYuan is a personal knowledge management system. Prior to 3.6.0, the /api/network/forwardProxy endpoint allows authenticated users to make arbitrary HTTP requests from the server. The endpoint accepts a user-controlled URL and makes HTTP requests to it, returning the full response body and headers. There is no URL validation to prevent requests to internal networks, localhost, or cloud metadata services. This vulnerability is fixed in 3.6.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/siyuan-note/siyuan/kernelGo | < 3.6.0 | 3.6.0 |
Affected products
4- ghsa-coords3 versionspkg:golang/github.com/siyuan-note/siyuan/kernelpkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0
< 3.6.0+ 2 more
- (no CPE)range: < 3.6.0
- (no CPE)range: < 0.0.20260317T205859-150000.1.152.1
- (no CPE)range: < 0.0.20260723T184607-160000.1.1
- Range: < 3.6.0
Patches
Vulnerability mechanics
References
3- github.com/siyuan-note/siyuan/security/advisories/GHSA-56cv-c5p2-j2wgnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-56cv-c5p2-j2wgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-32110ghsaADVISORY
News mentions
0No linked articles in our index yet.