CVE 9.1 CRITICAL

SiYuan has Arbitrary File Write via /api/file/copyFile leading to RCE_CVE-2026-25539

9.1 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Description

SiYuan is a personal knowledge management system. Prior to version 3.5.5, the /api/file/copyFile endpoint does not validate the dest parameter, allowing authenticated users to write files to arbitrary locations on the filesystem. This can lead to Remote Code Execution (RCE) by writing to sensitive locations such as cron jobs, SSH authorized_keys, or shell configuration files. This issue has been patched in version 3.5.5.

Basic Information

ID CVE-2026-25539
Source GitHub_M
Published Feb 4, 2026 at 21:39

Affected Product

Vendor siyuan-note
Product siyuan
Version < 3.5.5
Affected Versions siyuan-note siyuan < 3.5.5

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.