CVE-2025-67488 - CVE House
Back to Database
Status published High CVE-2025-67488

SiYuan: ZipSlip -> Arbitrary File Overwrite -> RCE

Vulnerability Description

SiYuan is self-hosted, open source personal knowledge management software. Versions 0.0.0-20251202123337-6ef83b42c7ce and below contain function importZipMd which is vulnerable to ZipSlips, allowing an authenticated user to overwrite files on the system. An authenticated user with access to the import functionality in notes is able to overwrite any file on the system, and can escalate to full code execution under some circumstances. A fix is planned for version 3.5.0.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-67488

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

siyuan-note

View all reports →

Affected Software

siyuan
Vulnerable Versions:
<= 0.0.0-20251202123337-6ef83b42c7ce

Timeline

Official Publish: December 9th, 2025
Last Modified: December 9th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses (CWE)