THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-73509 (HIGH 7.6) — OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.go authorizes only the source directory produced by user.JoinPath(req.SrcDir) and validates renameObject.NewName with checkRelativ

[NVD] CVE-2026-73509 (HIGH 7.6) — OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.go authorizes only the source directory produced by user.JoinPath(req.SrcDir) and validates renameObject.NewName with checkRelativ

lownvdPublished 2026-08-13

CVE-2026-73509 CVSS: 7.6 HIGH Published: 2026-08-13T15:20:17.623

OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.go authorizes only the source directory produced by user.JoinPath(req.SrcDir) and validates renameObject.NewName with checkRelativePath, but does not validate attacker-controlled renam

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73509