PT-2025-4297 · Unknown+1 · Siyuan Note+1

N0El4Kls

·

Published

2025-01-03

·

Updated

2025-05-14

·

CVE-2025-21609

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions SiYuan Note version 3.1.18
Description SiYuan Note is self-hosted, open source personal knowledge management software. The software has an arbitrary file deletion vulnerability that exists in the POST /api/history/getDocHistoryContent endpoint. An attacker can craft a payload to exploit this vulnerability, resulting in the deletion of arbitrary files on the server. The vulnerability can be reproduced by sending a crafted request to the /api/history/getDocHistoryContent endpoint, where the historyPath parameter in the payload is processed and can lead to file deletion if it does not satisfy certain conditions.
Recommendations For SiYuan Note version 3.1.18, upgrade to version 3.1.19, which is expected to include the fix for this vulnerability. As a temporary workaround, consider restricting access to the POST /api/history/getDocHistoryContent endpoint until the upgrade is applied. Additionally, avoid using the historyPath parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

Files Accessible to External Parties

Weakness Enumeration

Related Identifiers

CVE-2025-21609
GHSA-8FX8-PFFW-W498
GO-2025-3362
OPENSUSE-SU-2025:14624-1
OPENSUSE-SU-2025_0060-1
SUSE-SU-2025:0060-1

Affected Products

Siyuan Note
Suse