SiYuan has an arbitrary file write in the host via /api/asset/upload
Package
Affected versions
<= 0.0.0-20241210012039-5129ad926a21
Patched versions
None
Description
Published to the GitHub Advisory Database
Dec 11, 2024
Reviewed
Dec 11, 2024
Last updated
Dec 11, 2024
Summary
The /api/asset/upload endpoint in Siyuan is vulnerable to both arbitrary file write to the host and stored XSS (via the file write).
Impact
Arbitrary file write
References