File List Application Vulnerability in OpenList by OpenListTeam
CVE-2026-73509

7.6HIGH

Key Information:

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-73509?

The OpenList application, prior to version 4.2.4, contains a vulnerability in its file management system. The authenticated API endpoint for batch renaming files does not adequately validate the source name provided by users. This oversight allows an attacker with the necessary permissions to exploit path traversal segments. Consequently, the attacker can manipulate the file paths, resulting in potential unauthorized access to files not within their designated directories. This flaw poses significant risks, including loss of file integrity and the possibility of exposing sensitive file existence information through error messages and responses. Users are advised to upgrade to version 4.2.4 to mitigate these risks.

Affected Version(s)

OpenList < 4.2.4

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.