THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-h6cj-26g5-67fv (medium) — OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool

[GHSA] GHSA-h6cj-26g5-67fv (medium) — OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool

highgithub_advisoriesPublished 2026-09-03

GHSA-h6cj-26g5-67fv Severity: medium CVE: CVE-2026-75602

OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool

### Summary

Alist's offline-download feature (`POST /api/fs/add_offline_download` with `tool: "SimpleHttp"`) accepts an attacker-supplied URL, fetches it, and saves the bytes under a per-task temp directory before transf

Indicators of compromise

Original source: https://github.com/advisories/GHSA-h6cj-26g5-67fv