CVE-2026-25161
HIGHAlist < 3.57.0 - Authenticated Path Traversal via Filename Component Injection
Title source: llmDescription
Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application contains path traversal vulnerability in multiple file operation handlers. An authenticated attacker can bypass directory-level authorisation by injecting traversal sequences into filename components, enabling unauthorised file removal, movement and copying across user boundaries within the same storage mount. This issue has been patched in version 3.57.0.
References (2)
Core 2
Core References
Exploit, Vendor Advisory x_refsource_confirm
https://github.com/AlistGo/alist/security/advisories/GHSA-x4q4-7phh-42j9
Patch x_refsource_misc
https://github.com/AlistGo/alist/commit/b188288525b9a35c76535139311e7c036dab057e
Scores
CVSS v3
8.8
EPSS
0.0072
EPSS Percentile
49.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-22
Status
published
Products (2)
alist-org/alist
0 - 3.57.0Go
alistgo/alist
< 3.57.0
Published
Feb 04, 2026
Tracked Since
Feb 18, 2026