THREAT OPS › Threat News › [GHSA] GHSA-h6cj-26g5-67fv (medium) — OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool
[GHSA] GHSA-h6cj-26g5-67fv (medium) — OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool
GHSA-h6cj-26g5-67fv Severity: medium CVE: CVE-2026-75602
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool
### Summary
Alist's offline-download feature (`POST /api/fs/add_offline_download` with `tool: "SimpleHttp"`) accepts an attacker-supplied URL, fetches it, and saves the bytes under a per-task temp directory before transf
Indicators of compromise
- CVE-2026-75602cve
- CVE-2026-25161cve
- http://victim-alist.example/api/fs/add_offline_downloadurl
- http://attacker.com/payloadurl
Original source: https://github.com/advisories/GHSA-h6cj-26g5-67fv