Executive brief
Alist, a file list program that supports multiple storage providers, contains a security flaw where it fails to verify the identity of servers it connects to. This allows an attacker on the same network to intercept, read, and modify sensitive data, including login credentials and stored files. This could lead to a complete compromise of user data and unauthorized access to connected cloud storage accounts.
Technical details
Alist is vulnerable to improper certificate validation (CWE-295) because the `TlsInsecureSkipVerify` setting is hardcoded to `true` in the `DefaultConfig()` function within `internal/conf/config.go`. This configuration causes the application to skip TLS certificate verification for all outgoing storage driver communications. A network-positioned attacker can exploit this via DNS hijacking, ARP spoofing, or rogue access points to intercept traffic. Successful exploitation allows for the decryption of TLS traffic, enabling the theft of authentication cookies and the manipulation of data transmitted between Alist and backend storage providers. The issue is fixed in version 3.57.0.
Affected products
- AlistGo alist < 3.57.0
Timeline
- 2026-02-04: disclosed
- 2026-02-04: advisory
- 2026-02-04: patched: Fixed in version 3.57.0