CVE-2026-25539: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-25539 is an arbitrary file write vulnerability in SiYuan, a personal knowledge management system, affecting all versions up to and including 3.5.3. The /api/file/copyFile endpoint fails to validate the dest parameter, allowing authenticated users to write files to arbitrary locations on the host filesystem, which can lead to Remote Code Execution (RCE). The vulnerability was published on February 4, 2026, and patched in version 3.5.5. It carries a CVSS v3.1 base score of 9.1 (Critical) per the GitHub Security Advisory, or 7.2 (High) per NVD scoring (GitHub Advisory, Feedly).

Technical details

The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory / Path Traversal). In kernel/api/file.go, the copyFile function validates the src parameter via model.GetAssetAbsPath() but performs no validation on the dest parameter, allowing it to accept any absolute path on the filesystem. An authenticated attacker with an API token can first upload a malicious file to the workspace using /api/file/putFile, then invoke /api/file/copyFile with a crafted dest value pointing to sensitive system locations (e.g., /etc/cron.d/, ~/.ssh/authorized_keys, ~/.bashrc). The fix in commit d7f7907 adds a util.IsSensitivePath() check on the dest parameter before the copy operation is performed (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows an authenticated attacker to write arbitrary files anywhere on the host filesystem with the privileges of the SiYuan process, which may run as root. This enables full system compromise through RCE via cron job injection, persistent backdoor access via SSH authorized_keys manipulation, or command execution on user login via shell configuration files. The impact spans high confidentiality, integrity, and availability, with potential for lateral movement to other systems on the same network (GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly documented in the GitHub Security Advisory, demonstrating the full attack chain from file upload to RCE. There is no confirmed evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.0035 (0.35%), indicating low but non-zero probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible SiYuan instances running version 3.5.3 or earlier (default port 6806). Obtain a valid API token for an authenticated user.
  2. Prepare malicious payload: Create a shell script or other malicious file locally (e.g., a cron job backdoor or SSH key).
  3. Upload payload to workspace: Use the /api/file/putFile endpoint to upload the malicious file into the SiYuan workspace assets directory:
curl -X POST "http://target:6806/api/file/putFile" \
  -H "Authorization: Token <token>" \
  -F "path=/data/assets/malicious.sh" \
  -F "file=@-;filename=malicious.sh" <<< '#!/bin/sh\nid > /tmp/pwned.txt'
  1. Write to arbitrary location: Call /api/file/copyFile with the dest parameter set to a sensitive system path:
curl -X POST "http://target:6806/api/file/copyFile" \
  -H "Authorization: Token <token>" \
  -H "Content-Type: application/json" \
  -d '{"src": "assets/malicious.sh", "dest": "/etc/cron.d/backdoor"}'
  1. Achieve RCE: The cron daemon (or other trigger mechanism) executes the written file, resulting in command execution with the privileges of the SiYuan process. Alternatively, writing to ~/.ssh/authorized_keys grants persistent SSH access (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to /api/file/copyFile with dest values pointing outside the SiYuan workspace directory (e.g., /etc/, /root/, /tmp/, ~/.ssh/); POST requests to /api/file/putFile uploading shell scripts or SSH key files.
  • File System: Unexpected files in /etc/cron.d/, /etc/cron.hourly/, or other cron directories; new or modified ~/.ssh/authorized_keys; modified shell configuration files (.bashrc, .profile); unexpected scripts in /tmp/ with executable permissions.
  • Logs: SiYuan application logs (kernel/api/file.go) showing copyFile calls with absolute paths outside the workspace; web server access logs showing repeated POST requests to /api/file/copyFile or /api/file/putFile with unusual parameters.
  • Process: Unexpected child processes spawned by the SiYuan process (e.g., /bin/sh, bash, curl, wget); new cron jobs executing at regular intervals; unexpected SSH login sessions from unknown IP addresses (GitHub Advisory).

Mitigation and workarounds

Upgrade SiYuan to version 3.5.5 or later, which adds IsSensitivePath() validation on the dest parameter in the copyFile function to block writes to sensitive system locations. Until patching is possible, restrict access to the SiYuan API (port 6806) to trusted users only using network-level controls such as firewall rules or a reverse proxy with authentication. Additionally, run SiYuan under a least-privilege user account to limit the impact of any successful exploitation (GitHub Advisory, Patch Commit).

Community reactions

The vulnerability was reported by researcher "thxtech" and disclosed via GitHub's security advisory program. The Hacker Wire published a dedicated write-up on the arbitrary file write to RCE attack chain (The Hacker Wire). The CISA vulnerability bulletin for the week of February 2, 2026 included this CVE in its summary (CISA Bulletin). Community discussion was noted on Bluesky, with the vulnerability drawing attention as part of a broader pattern of security issues discovered in SiYuan around the same period.

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management