Skip to content

Arbitrary file write in the host via /api/asset/upload

High
88250 published GHSA-fqj6-whhx-47p7 Dec 11, 2024

Package

gomod https://github.com/siyuan-note/siyuan (Go)

Affected versions

v3.1.15

Patched versions

v3.1.16

Description

Summary

The /api/asset/upload endpoint in Siyuan is vulnerable to both arbitrary file write to the host and stored XSS (via the file write).

Impact

Arbitrary file write

Severity

High

CVE ID

CVE-2024-55659

Weaknesses

No CWEs

Credits