Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/OpenListTeam/OpenList/v4
  4. ›
  5. GHSA-86cx-wwf4-phq4

GHSA-86cx-wwf4-phq4: OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API

July 24, 2026 (updated August 18, 2026)

An authorization bypass vulnerability exists in the file sharing mechanism of Openlist. Due to a flawed, non-separator-aware path validation check, an authenticated user can create share links for files outside their restricted base directory. This allows an attacker to bypass tenant/user isolation and gain unauthorized read access to arbitrary files within the system.

References

  • github.com/OpenListTeam/OpenList/commit/59bd3431408578f420895457554700cc9a52375a
  • github.com/OpenListTeam/OpenList/releases/tag/v4.2.4
  • github.com/OpenListTeam/OpenList/security/advisories/GHSA-86cx-wwf4-phq4
  • github.com/advisories/GHSA-86cx-wwf4-phq4
  • nvd.nist.gov/vuln/detail/CVE-2026-69160

Code Behaviors & Features

Detect and mitigate GHSA-86cx-wwf4-phq4 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 4.2.4

Fixed versions

  • 4.2.4

Solution

Upgrade to version 4.2.4 or above.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-639: Authorization Bypass Through User-Controlled Key

Source file

go/github.com/OpenListTeam/OpenList/v4/GHSA-86cx-wwf4-phq4.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 22 Sep 2026 12:20:26 +0000.