File Upload Vulnerability in OpenList by OpenListTeam
CVE-2026-75602
6.5MEDIUM
What is CVE-2026-75602?
The OpenList software, which provides a file listing functionality with support for various storage options, has a flaw in its offline-download feature in versions before 4.2.3. This vulnerability allows an attacker to provide a malicious URL that could lead to the unauthorized creation, truncation, or overwriting of files on the server. The issue arises from the mishandling of the Content-Disposition header in user authentication scenarios, which permits non-admin users to exploit this vector and interact with files outside the intended temporary directory. This risk emphasizes the importance of proper input validation and access control measures within the software.
Affected Version(s)
OpenList < 4.2.3
