File List Application Vulnerability in OpenList by OpenListTeam
CVE-2026-73509
7.6HIGH
What is CVE-2026-73509?
The OpenList application, prior to version 4.2.4, contains a vulnerability in its file management system. The authenticated API endpoint for batch renaming files does not adequately validate the source name provided by users. This oversight allows an attacker with the necessary permissions to exploit path traversal segments. Consequently, the attacker can manipulate the file paths, resulting in potential unauthorized access to files not within their designated directories. This flaw poses significant risks, including loss of file integrity and the possibility of exposing sensitive file existence information through error messages and responses. Users are advised to upgrade to version 4.2.4 to mitigate these risks.
Affected Version(s)
OpenList < 4.2.4
