github.com/openlistteam/openlist/v4
A new AList Fork to Anti Trust Crisis
Activity
- Latest release
- 1w ago
- Total releases
- 22
- Cadence
- ~17 days
- Last 12 months
- 14
Reach
- Stars
- 24.5k
Details
- First release
- Jul 02, 2025
| Version | Released | |
|---|---|---|
v4.2.6
patch
|
v4.2.6
patch
Dependencies (94)
+ 86 more |
|
v4.2.5
patch
|
v4.2.5
patch
Dependencies (94)
+ 86 more |
|
v4.2.4
patch
|
v4.2.4
patch
Dependencies (95)
+ 87 more |
|
v4.2.3
patch
3 CVEs
CVE-2026-69160
GO-2026-6109
GHSA-86cx-wwf4-phq4
Aug 18, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-73509
GO-2026-6110
GHSA-95cv-r8x4-vh75
Aug 18, 2026
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList OpenList: Authenticated users can rename files outside their base path via batch rename Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-6113
GHSA-p6ph-3jx2-3337
Aug 18, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References
Updated Aug 18, 2026 · Source: OSV.dev |
v4.2.3
patch
Dependencies (95)
+ 87 more |
|
v4.2.2
patch
4 CVEs
CVE-2026-75602
GO-2026-6368
GHSA-h6cj-26g5-67fv
Sep 10, 2026
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList Fixed in
4.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-69160
GO-2026-6109
GHSA-86cx-wwf4-phq4
Aug 18, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-73509
GO-2026-6110
GHSA-95cv-r8x4-vh75
Aug 18, 2026
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList OpenList: Authenticated users can rename files outside their base path via batch rename Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-6113
GHSA-p6ph-3jx2-3337
Aug 18, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References
Updated Aug 18, 2026 · Source: OSV.dev |
v4.2.2
patch
Dependencies (95)
+ 87 more |
|
v4.2.1
patch
4 CVEs
CVE-2026-75602
GO-2026-6368
GHSA-h6cj-26g5-67fv
Sep 10, 2026
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList Fixed in
4.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-69160
GO-2026-6109
GHSA-86cx-wwf4-phq4
Aug 18, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-73509
GO-2026-6110
GHSA-95cv-r8x4-vh75
Aug 18, 2026
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList OpenList: Authenticated users can rename files outside their base path via batch rename Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-6113
GHSA-p6ph-3jx2-3337
Aug 18, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References
Updated Aug 18, 2026 · Source: OSV.dev |
v4.2.1
patch
Dependencies (96)
+ 88 more |
|
v4.2.0
minor
4 CVEs
CVE-2026-75602
GO-2026-6368
GHSA-h6cj-26g5-67fv
Sep 10, 2026
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList Fixed in
4.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-69160
GO-2026-6109
GHSA-86cx-wwf4-phq4
Aug 18, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-73509
GO-2026-6110
GHSA-95cv-r8x4-vh75
Aug 18, 2026
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList OpenList: Authenticated users can rename files outside their base path via batch rename Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-6113
GHSA-p6ph-3jx2-3337
Aug 18, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References
Updated Aug 18, 2026 · Source: OSV.dev |
v4.2.0
minor
Dependencies (96)
+ 88 more |
|
v4.1.10
patch
4 CVEs
CVE-2026-75602
GO-2026-6368
GHSA-h6cj-26g5-67fv
Sep 10, 2026
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList Fixed in
4.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-69160
GO-2026-6109
GHSA-86cx-wwf4-phq4
Aug 18, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-73509
GO-2026-6110
GHSA-95cv-r8x4-vh75
Aug 18, 2026
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList OpenList: Authenticated users can rename files outside their base path via batch rename Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-6113
GHSA-p6ph-3jx2-3337
Aug 18, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References
Updated Aug 18, 2026 · Source: OSV.dev |
v4.1.10
patch
Dependencies (95)
+ 87 more |
|
v4.1.9
patch
6 CVEs
CVE-2026-75602
GO-2026-6368
GHSA-h6cj-26g5-67fv
Sep 10, 2026
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList Fixed in
4.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-69160
GO-2026-6109
GHSA-86cx-wwf4-phq4
Aug 18, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-73509
GO-2026-6110
GHSA-95cv-r8x4-vh75
Aug 18, 2026
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList OpenList: Authenticated users can rename files outside their base path via batch rename Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-6113
GHSA-p6ph-3jx2-3337
Aug 18, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25060
GO-2026-4397
GHSA-wf93-3ghh-h389
Feb 05, 2026
OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25059
GO-2026-4396
GHSA-qmj2-8r24-xxcq
Feb 05, 2026
OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev |
v4.1.9
patch
Dependencies (93)
+ 85 more |
|
v4.1.8
patch
6 CVEs
CVE-2026-75602
GO-2026-6368
GHSA-h6cj-26g5-67fv
Sep 10, 2026
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList Fixed in
4.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-69160
GO-2026-6109
GHSA-86cx-wwf4-phq4
Aug 18, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-73509
GO-2026-6110
GHSA-95cv-r8x4-vh75
Aug 18, 2026
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList OpenList: Authenticated users can rename files outside their base path via batch rename Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-6113
GHSA-p6ph-3jx2-3337
Aug 18, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25060
GO-2026-4397
GHSA-wf93-3ghh-h389
Feb 05, 2026
OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25059
GO-2026-4396
GHSA-qmj2-8r24-xxcq
Feb 05, 2026
OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev |
v4.1.8
patch
Dependencies (92)
+ 84 more |
|
v4.1.7
patch
6 CVEs
CVE-2026-75602
GO-2026-6368
GHSA-h6cj-26g5-67fv
Sep 10, 2026
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList Fixed in
4.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-69160
GO-2026-6109
GHSA-86cx-wwf4-phq4
Aug 18, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-73509
GO-2026-6110
GHSA-95cv-r8x4-vh75
Aug 18, 2026
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList OpenList: Authenticated users can rename files outside their base path via batch rename Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-6113
GHSA-p6ph-3jx2-3337
Aug 18, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25060
GO-2026-4397
GHSA-wf93-3ghh-h389
Feb 05, 2026
OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25059
GO-2026-4396
GHSA-qmj2-8r24-xxcq
Feb 05, 2026
OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev |
v4.1.7
patch
Dependencies (92)
+ 84 more |
|
v4.1.6
patch
6 CVEs
CVE-2026-75602
GO-2026-6368
GHSA-h6cj-26g5-67fv
Sep 10, 2026
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList Fixed in
4.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-69160
GO-2026-6109
GHSA-86cx-wwf4-phq4
Aug 18, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-73509
GO-2026-6110
GHSA-95cv-r8x4-vh75
Aug 18, 2026
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList OpenList: Authenticated users can rename files outside their base path via batch rename Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-6113
GHSA-p6ph-3jx2-3337
Aug 18, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25060
GO-2026-4397
GHSA-wf93-3ghh-h389
Feb 05, 2026
OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25059
GO-2026-4396
GHSA-qmj2-8r24-xxcq
Feb 05, 2026
OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev |
v4.1.6
patch
Dependencies (91)
+ 83 more |
|
v4.1.5
patch
6 CVEs
CVE-2026-75602
GO-2026-6368
GHSA-h6cj-26g5-67fv
Sep 10, 2026
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList Fixed in
4.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-69160
GO-2026-6109
GHSA-86cx-wwf4-phq4
Aug 18, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-73509
GO-2026-6110
GHSA-95cv-r8x4-vh75
Aug 18, 2026
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList OpenList: Authenticated users can rename files outside their base path via batch rename Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-6113
GHSA-p6ph-3jx2-3337
Aug 18, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25060
GO-2026-4397
GHSA-wf93-3ghh-h389
Feb 05, 2026
OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25059
GO-2026-4396
GHSA-qmj2-8r24-xxcq
Feb 05, 2026
OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev |
v4.1.5
patch
Dependencies (91)
+ 83 more |
|
v4.1.4
patch
6 CVEs
CVE-2026-75602
GO-2026-6368
GHSA-h6cj-26g5-67fv
Sep 10, 2026
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList Fixed in
4.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-69160
GO-2026-6109
GHSA-86cx-wwf4-phq4
Aug 18, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-73509
GO-2026-6110
GHSA-95cv-r8x4-vh75
Aug 18, 2026
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList OpenList: Authenticated users can rename files outside their base path via batch rename Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-6113
GHSA-p6ph-3jx2-3337
Aug 18, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25060
GO-2026-4397
GHSA-wf93-3ghh-h389
Feb 05, 2026
OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25059
GO-2026-4396
GHSA-qmj2-8r24-xxcq
Feb 05, 2026
OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev |
v4.1.4
patch
Dependencies (88)
+ 80 more |
|
v4.1.3
patch
6 CVEs
CVE-2026-75602
GO-2026-6368
GHSA-h6cj-26g5-67fv
Sep 10, 2026
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList Fixed in
4.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-69160
GO-2026-6109
GHSA-86cx-wwf4-phq4
Aug 18, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-73509
GO-2026-6110
GHSA-95cv-r8x4-vh75
Aug 18, 2026
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList OpenList: Authenticated users can rename files outside their base path via batch rename Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-6113
GHSA-p6ph-3jx2-3337
Aug 18, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25060
GO-2026-4397
GHSA-wf93-3ghh-h389
Feb 05, 2026
OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25059
GO-2026-4396
GHSA-qmj2-8r24-xxcq
Feb 05, 2026
OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev |
v4.1.3
patch
Dependencies (85)
+ 77 more |
|
v4.1.2
patch
6 CVEs
CVE-2026-75602
GO-2026-6368
GHSA-h6cj-26g5-67fv
Sep 10, 2026
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList Fixed in
4.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-69160
GO-2026-6109
GHSA-86cx-wwf4-phq4
Aug 18, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-73509
GO-2026-6110
GHSA-95cv-r8x4-vh75
Aug 18, 2026
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList OpenList: Authenticated users can rename files outside their base path via batch rename Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-6113
GHSA-p6ph-3jx2-3337
Aug 18, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25060
GO-2026-4397
GHSA-wf93-3ghh-h389
Feb 05, 2026
OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25059
GO-2026-4396
GHSA-qmj2-8r24-xxcq
Feb 05, 2026
OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev |
v4.1.2
patch
Dependencies (85)
+ 77 more |
|
v4.1.1
patch
6 CVEs
CVE-2026-75602
GO-2026-6368
GHSA-h6cj-26g5-67fv
Sep 10, 2026
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList Fixed in
4.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-69160
GO-2026-6109
GHSA-86cx-wwf4-phq4
Aug 18, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-73509
GO-2026-6110
GHSA-95cv-r8x4-vh75
Aug 18, 2026
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList OpenList: Authenticated users can rename files outside their base path via batch rename Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-6113
GHSA-p6ph-3jx2-3337
Aug 18, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25060
GO-2026-4397
GHSA-wf93-3ghh-h389
Feb 05, 2026
OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25059
GO-2026-4396
GHSA-qmj2-8r24-xxcq
Feb 05, 2026
OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev |
v4.1.1
patch
Dependencies (85)
+ 77 more |
|
v4.1.0
minor
6 CVEs
CVE-2026-75602
GO-2026-6368
GHSA-h6cj-26g5-67fv
Sep 10, 2026
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList Fixed in
4.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-69160
GO-2026-6109
GHSA-86cx-wwf4-phq4
Aug 18, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-73509
GO-2026-6110
GHSA-95cv-r8x4-vh75
Aug 18, 2026
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList OpenList: Authenticated users can rename files outside their base path via batch rename Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-6113
GHSA-p6ph-3jx2-3337
Aug 18, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25060
GO-2026-4397
GHSA-wf93-3ghh-h389
Feb 05, 2026
OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25059
GO-2026-4396
GHSA-qmj2-8r24-xxcq
Feb 05, 2026
OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev |
v4.1.0
minor
Dependencies (85)
+ 77 more |
|
v4.0.9
patch
6 CVEs
CVE-2026-75602
GO-2026-6368
GHSA-h6cj-26g5-67fv
Sep 10, 2026
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList Fixed in
4.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-69160
GO-2026-6109
GHSA-86cx-wwf4-phq4
Aug 18, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-73509
GO-2026-6110
GHSA-95cv-r8x4-vh75
Aug 18, 2026
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList OpenList: Authenticated users can rename files outside their base path via batch rename Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-6113
GHSA-p6ph-3jx2-3337
Aug 18, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25060
GO-2026-4397
GHSA-wf93-3ghh-h389
Feb 05, 2026
OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25059
GO-2026-4396
GHSA-qmj2-8r24-xxcq
Feb 05, 2026
OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev |
v4.0.9
patch
Dependencies (85)
+ 77 more |
|
v4.0.8
patch
6 CVEs
CVE-2026-75602
GO-2026-6368
GHSA-h6cj-26g5-67fv
Sep 10, 2026
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList Fixed in
4.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-69160
GO-2026-6109
GHSA-86cx-wwf4-phq4
Aug 18, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-73509
GO-2026-6110
GHSA-95cv-r8x4-vh75
Aug 18, 2026
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList OpenList: Authenticated users can rename files outside their base path via batch rename Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-6113
GHSA-p6ph-3jx2-3337
Aug 18, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25060
GO-2026-4397
GHSA-wf93-3ghh-h389
Feb 05, 2026
OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25059
GO-2026-4396
GHSA-qmj2-8r24-xxcq
Feb 05, 2026
OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev |
v4.0.8
patch
Dependencies (85)
+ 77 more |
|
v4.0.7
patch
6 CVEs
CVE-2026-75602
GO-2026-6368
GHSA-h6cj-26g5-67fv
Sep 10, 2026
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList Fixed in
4.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-69160
GO-2026-6109
GHSA-86cx-wwf4-phq4
Aug 18, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-73509
GO-2026-6110
GHSA-95cv-r8x4-vh75
Aug 18, 2026
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList OpenList: Authenticated users can rename files outside their base path via batch rename Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-6113
GHSA-p6ph-3jx2-3337
Aug 18, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25060
GO-2026-4397
GHSA-wf93-3ghh-h389
Feb 05, 2026
OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25059
GO-2026-4396
GHSA-qmj2-8r24-xxcq
Feb 05, 2026
OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev |
v4.0.7
patch
Dependencies (85)
+ 77 more |
|
v4.0.6
initial
6 CVEs
CVE-2026-75602
GO-2026-6368
GHSA-h6cj-26g5-67fv
Sep 10, 2026
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList Fixed in
4.2.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-69160
GO-2026-6109
GHSA-86cx-wwf4-phq4
Aug 18, 2026
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-73509
GO-2026-6110
GHSA-95cv-r8x4-vh75
Aug 18, 2026
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList OpenList: Authenticated users can rename files outside their base path via batch rename Fixed in
4.2.4
References Updated Aug 18, 2026 · Source: OSV.dev
GO-2026-6113
GHSA-p6ph-3jx2-3337
Aug 18, 2026
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList Fixed in
4.2.4
References
Updated Aug 18, 2026 · Source: OSV.dev
CVE-2026-25060
GO-2026-4397
GHSA-wf93-3ghh-h389
Feb 05, 2026
OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList OpenList has Insecure TLS Default Configuration in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev
CVE-2026-25059
GO-2026-4396
GHSA-qmj2-8r24-xxcq
Feb 05, 2026
OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList OpenList vulnerable to Path Traversal in file copy and remove handlers in github.com/OpenListTeam/OpenList Fixed in
4.1.10
References
Updated Feb 05, 2026 · Source: OSV.dev |
v4.0.6
initial
Dependencies (85)
+ 77 more |