ZipSlip Vulnerability in SiYuan Open Source Knowledge Management Software
CVE-2025-67488

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
9 December 2025

What is CVE-2025-67488?

SiYuan is an open-source personal knowledge management tool that is susceptible to a ZipSlip vulnerability due to its importZipMd function. This weakness allows authenticated users with access to the import feature to potentially overwrite system files. If exploited, under certain conditions, this may lead to full code execution on the host system. A patch is anticipated in version 3.5.0 to resolve this issue.

Affected Version(s)

siyuan <= 0.0.0-20251202123337-6ef83b42c7ce

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-67488 : ZipSlip Vulnerability in SiYuan Open Source Knowledge Management Software