THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-75602 (MEDIUM 6.5) — OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp" accepts an attacker-supplied URL and saves its bytes under a per-task temporary directory before transferr

[NVD] CVE-2026-75602 (MEDIUM 6.5) — OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp" accepts an attacker-supplied URL and saves its bytes under a per-task temporary directory before transferr

mednvdPublished 2026-09-03

CVE-2026-75602 CVSS: 6.5 MEDIUM Published: 2026-09-03T17:17:23.757

OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp" accepts an attacker-supplied URL and saves its bytes under a per-task temporary directory before transferring them to the user's destination storage. The temp

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-75602