CVE-2026-32110 describes a Server-Side Request Forgery (SSRF) vulnerability in SiYuan (b3log siyuan) versions prior to 3.6.0. An authenticated user can exploit the /api/network/forwardProxy endpoint to make arbitrary HTTP requests from the server, as there is no URL validation to restrict access to internal networks, localhost, or cloud metadata services. This flaw carries a CVSS score of 8.3 HIGH, indicating a severe risk with high confidentiality and integrity impacts, requiring only low privileges and network access for exploitation. Currently, there are no known public exploits or active exploitation reported in CISA's KEV catalog, and community attention remains low with minimal mentions and articles.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.6.0CPE matchmatch criteria | cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.