Junglewise Threat Intelligence

CVE-2026-25161: Alist path traversal in multiple file operation handlers

CVE-2026-25161 · Severity: high · CVSS 8.8 · Published 2026-02-04

Technologies: github.com/alist-org/alist/v3 (Go), github.com/alist-org/alist (Go). Vendors: Go.

Executive brief

Alist, a file list program that supports multiple storage backends, is vulnerable to a security flaw that allows users to access files they shouldn't see. An authenticated user can use specially crafted file names to "jump" out of their assigned folder and delete, move, or copy files belonging to other users or administrators. This could lead to the loss of sensitive data or unauthorized modification of files on shared storage systems.

Technical details

A path traversal vulnerability (CWE-22) exists in Alist's file operation handlers, specifically within 'server/handles/fsmanage.go' and 'server/handles/fsbatch.go'. The application fails to properly sanitize filename components in 'req.Names', 'renameObject.SrcName', and 'renameObject.NewName' before concatenating them with directory paths using 'stdpath.Join()' or 'fmt.Sprintf()'. An authenticated attacker can inject '../' sequences to escape their assigned base path. This enables unauthorized file operations (remove, copy, rename, move) across user boundaries within the same storage mount. The issue is fixed in version 3.57.0.

Affected products

  • AlistGo alist < 3.57.0

Timeline

  • 2026-02-04: disclosed
  • 2026-02-04: advisory
  • 2026-02-04: patched: Fixed in version 3.57.0

References

Related threats