CVE-2026-25539Disclosure(b3log / siyuan)

LOWCVSS 7.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch b3log siyuan systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

SiYuan is a personal knowledge management system. Prior to version 3.5.5, the /api/file/copyFile endpoint does not validate the dest parameter, allowing authenticated users to write files to arbitrary locations on the filesystem. This can lead to Remote Code Execution (RCE) by writing to sensitive locations such as cron jobs, SSH authorized_keys, or shell configuration files. This issue has been patched in version 3.5.5.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • siyuan

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 3d ago at 2 mentions (2026-02-04); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
siyuan

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-02-04: 2Mentions · 2026-02-05: 1Mentions · 2026-02-06: 1Mentions · 2026-03-22: 1PoC Mentioned / Linked · 2026-02-04: 1Patch / Workaround · 2026-02-04: 1Technical Details · 2026-02-04: 2Technical Details · 2026-02-05: 1Technical Details · 2026-02-06: 1Technical Details · 2026-03-22: 102-0402-0502-0603-22
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-042
Disclosure2
2026-02-051
Disclosure1
2026-02-061
Disclosure1
2026-03-221
Disclosure1
Full discourse5 posts
  • White Rabbitx@TheRabbitPy
    Disclosure

    🚨 CVE-2026-25539 (CVSS 9.1): SiYuan knowledge mgmt <3.5.5 /api/file/copyFile arbitrary file write → RCE via cron/SSH keys. PKM apps risky! https://feedly.com/cve/severity/9-10?page=5

    Post summary

    The tweet announces CVE-2026-25539, a high‑severity flaw in SiYuan <3.5.5 allowing arbitrary file writes via /api/file/copyFile that can be leveraged for remote code execution through cron/SSH keys.

    0203083
    374 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    SiYuan is affected by a critical arbitrary file write vulnerability (CVE-2026-25539) via /api/file/copyFile, leading to RCE. Review #infosec posture for #SiYuan deployments. Details: https://www.pulsepatch.io/posts/cve-2026-25539-siyuan-arbitrary-file-write

    Post summary

    SiYuan suffers a critical arbitrary file write flaw (CVE-2026-25539) that can lead to remote code execution via the /api/file/copyFile endpoint, as recently disclosed.

    0000056
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25539 Remote Code Execution in SiYuan Knowledge Management System Prior to 3.5.5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25539

    Post summary

    A remote code execution vulnerability (CVE-2026-25539) has been identified in SiYuan Knowledge Management System versions earlier than 3.5.5.

    0000074
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25539 SiYuan is a personal knowledge management system. Prior to version 3.5.5, the /api/file/copyFile endpoint does not validate the dest parameter, allowing authenticated… https://www.cve.org/CVERecord?id=CVE-2026-25539

    Post summary

    The post discloses that SiYuan’s /api/file/copyFile endpoint lacks dest‑parameter validation for authenticated users, and that version 3.5.5 addresses this flaw.

    00000146
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-25539: SiYuan has Arbitrary File Write ... Unvalidated dest parameter in SiYuan's copyFile API creates classic path traversal-&gt;RCE kill chain via crontab/SSH keys... https://zerodaysignal.com/vulnerability/CVE-2026-25539 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post reveals CVE-2026-25539, noting an unvalidated dest parameter in SiYuan’s copyFile API that enables path traversal and remote code execution via crontab/SSH keys. It links to a vulnerability page but provides no patch, exploit, or active exploitation details.

    0000091
    132 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appb3logsiyuan---

Explore more