CVE-2025-21609

CRITICAL
Published Jan 3, 2025 Modified May 14, 2025 CWE-459 CWE-552

Description

SiYuan is self-hosted, open source personal knowledge management software. SiYuan Note version 3.1.18 has an arbitrary file deletion vulnerability. The vulnerability exists in the `POST /api/history/getDocHistoryContent` endpoint. An attacker can craft a payload to exploit this vulnerability, resulting in the deletion of arbitrary files on the server. Commit d9887aeec1b27073bec66299a9a4181dc42969f3 fixes this vulnerability and is expected to be available in version 3.1.19.

CVSS v3.1 Score

9.1
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Weakness Type (CWE)

CWE-459 CWE-459
CWE-552 CWE-552

Affected Products

Vendor Product
b3log siyuan

References

Frequently Asked Questions

What is CVE-2025-21609? +
SiYuan is self-hosted, open source personal knowledge management software. SiYuan Note version 3.1.18 has an arbitrary file deletion vulnerability. The vulnerability exists in the `POST /api/history/getDocHistoryContent` endpoint. An attacker can craft a payload to exploit this vulnerability, resulting in the deletion of arbitrary files on the server. Commit d9887aeec1b27073bec66299a9a4181dc42969f3 fixes this vulnerability and is expected to be available in version 3.1.19. It has a CVSS v3.1 base score of 9.1 (CRITICAL).
How severe is CVE-2025-21609? +
CVE-2025-21609 has a CVSS v3.1 score of 9.1 out of 10, rated CRITICAL. This is a critical vulnerability that should be patched immediately.
What products are affected by CVE-2025-21609? +
CVE-2025-21609 affects products from b3log, specifically: siyuan. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2025-21609? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2025-21609 — free, no signup required.

Start Free Scan