THREAT OPS › Threat News › [NVD] CVE-2026-75602 (MEDIUM 6.5) — OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp" accepts an attacker-supplied URL and saves its bytes under a per-task temporary directory before transferr
[NVD] CVE-2026-75602 (MEDIUM 6.5) — OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp" accepts an attacker-supplied URL and saves its bytes under a per-task temporary directory before transferr
CVE-2026-75602 CVSS: 6.5 MEDIUM Published: 2026-09-03T17:17:23.757
OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp" accepts an attacker-supplied URL and saves its bytes under a per-task temporary directory before transferring them to the user's destination storage. The temp
Indicators of compromise
- CVE-2026-75602cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-75602