CVE-2026-25161

HIGH

Alist < 3.57.0 - Authenticated Path Traversal via Filename Component Injection

Title source: llm
STIX 2.1

Description

Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application contains path traversal vulnerability in multiple file operation handlers. An authenticated attacker can bypass directory-level authorisation by injecting traversal sequences into filename components, enabling unauthorised file removal, movement and copying across user boundaries within the same storage mount. This issue has been patched in version 3.57.0.

Scores

CVSS v3 8.8
EPSS 0.0072
EPSS Percentile 49.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (2)
alist-org/alist 0 - 3.57.0Go
alistgo/alist < 3.57.0
Published Feb 04, 2026
Tracked Since Feb 18, 2026