THREAT OPS › Threat News › [NVD] CVE-2026-73509 (HIGH 7.6) — OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.go authorizes only the source directory produced by user.JoinPath(req.SrcDir) and validates renameObject.NewName with checkRelativ
[NVD] CVE-2026-73509 (HIGH 7.6) — OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.go authorizes only the source directory produced by user.JoinPath(req.SrcDir) and validates renameObject.NewName with checkRelativ
CVE-2026-73509 CVSS: 7.6 HIGH Published: 2026-08-13T15:20:17.623
OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.go authorizes only the source directory produced by user.JoinPath(req.SrcDir) and validates renameObject.NewName with checkRelativePath, but does not validate attacker-controlled renam
Indicators of compromise
- CVE-2026-73509cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73509