PT-2026-6278 · Alist · Alist
A7Um
+1
·
Publicado
2026-02-04
·
Atualizado
2026-02-06
·
CVE-2026-25160
CVSS v3.1
9.1
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Alist versions prior to 3.57.0
Description
Alist, a file list program powered by Gin and Solidjs, has a configuration issue where TLS certificate verification is disabled by default for all outgoing storage driver communications. This allows for potential Man-in-the-Middle (MitM) attacks, enabling decryption, theft, and manipulation of data transmitted during storage operations. This compromises the confidentiality and integrity of user data.
Recommendations
Update to version 3.57.0 or later.
Exploit
Correção
Improper Certificate Validation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alist