CVE-2026-25539 | SiYuan up to 3.5.4 File Endpoint /api/file/copyFile dest path traversal (GHSA-c4jr-5q7w-f6r9 / EUVD-2026-5331)
A vulnerability classified as critical has been found in SiYuan up to 3.5.4. Affected by this vulnerability is an unknown functionality of the file /api/file/copyFile of the component File Endpoint. The manipulation of the argument dest leads to path traversal.
This vulnerability is traded as CVE-2026-25539. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.