PT-2026-6279 · Alist · Alist

A7Um

+1

·

Publicado

2026-02-04

·

Atualizado

2026-02-06

·

CVE-2026-25161

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Alist versions prior to 3.57.0
Description Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. The application contains a path traversal issue in multiple file operation handlers. An authenticated attacker can bypass directory-level authorization by injecting traversal sequences into filename components. This allows unauthorized file removal, movement, and copying across user boundaries within the same storage mount. The vulnerability affects file operations and potentially compromises data integrity and confidentiality.
Recommendations Update to version 3.57.0 or later.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-25161
GHSA-X4Q4-7PHH-42J9
GO-2026-4415
SUSE-SU-2026:0403-1

Produtos afetados

Alist