Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-c4jr-5q7w-f6r9 | SiYuan has Arbitrary File Write via /api/file/copyFile leading to RCE |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 05 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 05 Feb 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siyuan
Siyuan siyuan |
|
| Vendors & Products |
Siyuan
Siyuan siyuan |
Wed, 04 Feb 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SiYuan is a personal knowledge management system. Prior to version 3.5.5, the /api/file/copyFile endpoint does not validate the dest parameter, allowing authenticated users to write files to arbitrary locations on the filesystem. This can lead to Remote Code Execution (RCE) by writing to sensitive locations such as cron jobs, SSH authorized_keys, or shell configuration files. This issue has been patched in version 3.5.5. | |
| Title | SiYuan has Arbitrary File Write via /api/file/copyFile leading to RCE | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-05T18:32:27.657Z
Reserved: 2026-02-02T19:59:47.374Z
Link: CVE-2026-25539
Updated: 2026-02-05T18:32:15.638Z
Status : Awaiting Analysis
Published: 2026-02-04T22:16:00.083
Modified: 2026-02-05T19:15:56.253
Link: CVE-2026-25539
No data.
OpenCVE Enrichment
Updated: 2026-02-05T11:39:22Z
Github GHSA