Headline
GHSA-pmg2-rph8-p8r6: Alist vulnerable to Path Traversal
In versions of Alist prior to 3.6.0, a user with only file upload permission can bypass the base path restriction by using ‘… /’ to bypass the base path restriction and upload files to an arbitrary path.
Alist vulnerable to Path Traversal
Moderate severity GitHub Reviewed Published Dec 16, 2022 • Updated Dec 16, 2022
Related news
CVE-2022-45969: Directory traversal file upload vulnerability · Issue #2449 · alist-org/alist
Alist v3.4.0 is vulnerable to Directory Traversal,