Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-95cv-r8x4-vh75 | OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal |
Thu, 13 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.go authorizes only the source directory produced by user.JoinPath(req.SrcDir) and validates renameObject.NewName with checkRelativePath, but does not validate attacker-controlled renameObject.SrcName, supplied as src_name, before concatenating it with the authorized path and passing the result to fs.Rename. A user with rename permission can use traversal segments in src_name to make path normalization select a file outside the authorized directory and configured base path, resulting in cross-user file integrity loss, limited availability impact, and file-existence disclosure through success or error responses. This issue is fixed in version 4.2.4. | |
| Title | OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-13T15:20:16.263Z
Reserved: 2026-08-12T19:00:33.736Z
Link: CVE-2026-73509
Updated: 2026-08-13T15:20:08.780Z
Status : Received
Published: 2026-08-13T15:20:17.623
Modified: 2026-08-13T16:19:05.083
Link: CVE-2026-73509
No data.
OpenCVE Enrichment
Updated: 2026-08-13T16:30:03Z
Github GHSA