Skip to content

SiYuan's renderSprig has a missing admin check that allows any user to read full workspace DB

Moderate severity GitHub Reviewed Published Mar 13, 2026 in siyuan-note/siyuan • Updated Mar 16, 2026

No closed alerts for this advisory

Give feedback on Dependabot alerts