PT-2026-6279 · Alist · Alist
A7Um
+1
·
Publicado
2026-02-04
·
Atualizado
2026-02-06
·
CVE-2026-25161
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Alist versions prior to 3.57.0
Description
Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. The application contains a path traversal issue in multiple file operation handlers. An authenticated attacker can bypass directory-level authorization by injecting traversal sequences into filename components. This allows unauthorized file removal, movement, and copying across user boundaries within the same storage mount. The vulnerability affects file operations and potentially compromises data integrity and confidentiality.
Recommendations
Update to version 3.57.0 or later.
Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alist