Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-25539

Опубликовано: 04 фев. 2026
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

SiYuan is a personal knowledge management system. Prior to version 3.5.5, the /api/file/copyFile endpoint does not validate the dest parameter, allowing authenticated users to write files to arbitrary locations on the filesystem. This can lead to Remote Code Execution (RCE) by writing to sensitive locations such as cron jobs, SSH authorized_keys, or shell configuration files. This issue has been patched in version 3.5.5.

EPSS

Процентиль: 50%
0.00268
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.1
github
9 дней назад

SiYuan has Arbitrary File Write via /api/file/copyFile leading to RCE

EPSS

Процентиль: 50%
0.00268
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-22