ZipSlip Vulnerability in SiYuan Open Source Knowledge Management Software
CVE-2025-67488

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
9 December 2025

What is CVE-2025-67488?

SiYuan is an open-source personal knowledge management tool that is susceptible to a ZipSlip vulnerability due to its importZipMd function. This weakness allows authenticated users with access to the import feature to potentially overwrite system files. If exploited, under certain conditions, this may lead to full code execution on the host system. A patch is anticipated in version 3.5.0 to resolve this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

siyuan <= 0.0.0-20251202123337-6ef83b42c7ce

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.