VDB
Sign up
MEDIUM5.4

GHSA-957m-g6rf-4c2m

Alist Cross-site Scripting vulnerability

Details

Alist v3.5.1 is vulnerable to Cross Site Scripting (XSS) via the bulletin board.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/alist-org/alist/v3
Introduced in: 0

No fixed version published yet for github.com/alist-org/alist/v3 (go modules). Pin to a known-safe version or switch to an alternative.

References