GHSA-4r66-7rcv-x46x: SiYuan vulnerable to RCE via zip slip and Command Injection via PandocBin
Siyuan is vulnerable to RCE. The issue stems from a “Zip Slip” vulnerability during zip file extraction, combined with the ability to overwrite system executables and subsequently trigger their execution.
References
Code Behaviors & Features
Detect and mitigate GHSA-4r66-7rcv-x46x with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →