← Back to CVE List

CVE-2025-21609

Published: 2025-01-03T17:15Z
Last Modified: 2025-01-03T17:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
SiYuan is self-hosted, open source personal knowledge management software. SiYuan Note version 3.1.18 has an arbitrary file deletion vulnerability. The vulnerability exists in the `POST /api/history/getDocHistoryContent` endpoint. An attacker can craft a payload to exploit this vulnerability, resulting in the deletion of arbitrary files on the server. Commit d9887aeec1b27073bec66299a9a4181dc42969f3 fixes this vulnerability and is expected to be available in version 3.1.19. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt