PT-2026-6318 · Siyuan · Siyuan

Thxtech

·

Published

2026-01-29

·

Updated

2026-02-04

·

CVE-2026-25539

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.5.5
Description SiYuan is a personal knowledge management system. The /api/file/copyFile endpoint does not validate the dest parameter. This allows authenticated users to write files to arbitrary locations on the filesystem, potentially leading to Remote Code Execution (RCE) by writing to sensitive locations such as cron jobs, SSH authorized keys, or shell configuration files.
Recommendations Update to version 3.5.5 or later.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-25539
GHSA-C4JR-5Q7W-F6R9
GO-2026-4387

Affected Products

Siyuan