SiYuan is self-hosted, open source personal knowledge management software. SiYuan Note version 3.1.18 has an arbitrary file deletion vulnerability. The vulnerability exists in the `POST /api/history/getDocHistoryContent` endpoint. An attacker can craft a payload to exploit this vulnerability, resulting in the deletion of arbitrary files on the server. Commit d9887aeec1b27073bec66299a9a4181dc42969f3 fixes this vulnerability and is expected to be available in version 3.1.19.
History

Fri, 03 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jan 2025 16:45:00 +0000

Type Values Removed Values Added
Description SiYuan is self-hosted, open source personal knowledge management software. SiYuan Note version 3.1.18 has an arbitrary file deletion vulnerability. The vulnerability exists in the `POST /api/history/getDocHistoryContent` endpoint. An attacker can craft a payload to exploit this vulnerability, resulting in the deletion of arbitrary files on the server. Commit d9887aeec1b27073bec66299a9a4181dc42969f3 fixes this vulnerability and is expected to be available in version 3.1.19.
Title SiYuan has an arbitrary file deletion vulnerability
Weaknesses CWE-459
CWE-552
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-01-03T16:26:36.420Z

Updated: 2025-01-03T17:14:23.915Z

Reserved: 2024-12-29T03:00:24.712Z

Link: CVE-2025-21609

cve-icon Vulnrichment

Updated: 2025-01-03T17:14:16.382Z

cve-icon NVD

Status : Received

Published: 2025-01-03T17:15:09.147

Modified: 2025-01-03T17:15:09.147

Link: CVE-2025-21609

cve-icon Redhat

No data.