HIGH8.8
GHSA-hh54-53m7-7ffj
alist Incorrect Access Control vulnerability
Details
alist <=3.16.3 is vulnerable to Incorrect Access Control. Low privilege accounts can upload any file.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/alist-org/alist/v3
Introduced in:
0No fixed version published yet for github.com/alist-org/alist/v3 (go modules). Pin to a known-safe version or switch to an alternative.