CVE-2026-25539

CRITICAL

B3log Siyuan < 3.5.3 - Path Traversal

Title source: rule
STIX 2.1

Description

SiYuan is a personal knowledge management system. Prior to version 3.5.5, the /api/file/copyFile endpoint does not validate the dest parameter, allowing authenticated users to write files to arbitrary locations on the filesystem. This can lead to Remote Code Execution (RCE) by writing to sensitive locations such as cron jobs, SSH authorized_keys, or shell configuration files. This issue has been patched in version 3.5.5.

Scores

CVSS v3 9.1
EPSS 0.0024
EPSS Percentile 47.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (2)
b3log/siyuan < 3.5.3
siyuan-note/siyuan 0Go
Published Feb 04, 2026
Tracked Since Feb 18, 2026