ZipSlip Vulnerability in SiYuan Open Source Knowledge Management Software
CVE-2025-67488
7.8HIGH
What is CVE-2025-67488?
SiYuan is an open-source personal knowledge management tool that is susceptible to a ZipSlip vulnerability due to its importZipMd function. This weakness allows authenticated users with access to the import feature to potentially overwrite system files. If exploited, under certain conditions, this may lead to full code execution on the host system. A patch is anticipated in version 3.5.0 to resolve this issue.
Affected Version(s)
siyuan <= 0.0.0-20251202123337-6ef83b42c7ce
