White Rabbitx[verified]@TheRabbitPyDisclosure
The tweet announces CVE-2026-25539, a high‑severity flaw in SiYuan <3.5.5 allowing arbitrary file writes via /api/file/copyFile that can be leveraged for remote code execution through cron/SSH keys.
PulsePatch.io@pulsepatchioDisclosure
SiYuan suffers a critical arbitrary file write flaw (CVE-2026-25539) that can lead to remote code execution via the /api/file/copyFile endpoint, as recently disclosed.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A remote code execution vulnerability (CVE-2026-25539) has been identified in SiYuan Knowledge Management System versions earlier than 3.5.5.
CVE@CVEnewDisclosure
The post discloses that SiYuan’s /api/file/copyFile endpoint lacks dest‑parameter validation for authenticated users, and that version 3.5.5 addresses this flaw.
0day Signal@0dayPublishingDisclosure
The post reveals CVE-2026-25539, noting an unvalidated dest parameter in SiYuan’s copyFile API that enables path traversal and remote code execution via crontab/SSH keys. It links to a vulnerability page but provides no patch, exploit, or active exploitation details.