Security: OpenListTeam/OpenList
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Meta password bypassed via path-segment case variationGHSA-x6r4-p647-hjcf published
Sep 6, 2026 by jyxjjjHigh -
Arbitrary File Read via Path Prefix Confusion in Share Creation APIGHSA-86cx-wwf4-phq4 published
Jul 23, 2026 by xrgzsModerate -
OpenList Bleve search authorization bypass via non-separator-aware BasePath validationGHSA-p6ph-3jx2-3337 published
Jul 23, 2026 by xrgzsModerate -
Authenticated users can rename files outside their base path via batch rename `src_name` traversalGHSA-95cv-r8x4-vh75 published
Jul 23, 2026 by xrgzsHigh -
Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download toolGHSA-h6cj-26g5-67fv published
Jul 9, 2026 by jyxjjjModerate -
Path Traversal in file copy and remove handlersGHSA-qmj2-8r24-xxcq published
Jan 31, 2026 by jyxjjjHigh -
Insecure TLS Default ConfigurationGHSA-wf93-3ghh-h389 published
Jan 31, 2026 by jyxjjjHigh -
XSS Attack in built-in Markdown ViewerGHSA-2hw3-h8qx-hqqp published
Jun 18, 2025 by jyxjjjModerate