—
GO-2026-4415
Alist vulnerable to Path Traversal in multiple file operation handlers in github.com/alist-org/alist
Quick fix
GO-2026-4415 — github.com/alist-org/alist/v3: upgrade to the fixed version with the command below.
go get github.com/alist-org/alist/v3@v3.57.0Details
Alist vulnerable to Path Traversal in multiple file operation handlers in github.com/alist-org/alist
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/alist-org/alist
Introduced in:
0No fixed version published yet for github.com/alist-org/alist (go modules). Pin to a known-safe version or switch to an alternative.
Go/github.com/alist-org/alist/v3
Introduced in:
0Fixed in: 3.57.0Fix
go get github.com/alist-org/alist/v3@v3.57.0References
- https://github.com/AlistGo/alist/security/advisories/GHSA-x4q4-7phh-42j9[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-25161[ADVISORY]
- https://github.com/AlistGo/alist/blob/b4d9beb49cba399842a54fcc33bc95a4a09b7bd4/server/handles/fsbatch.go#L188-L189[WEB]
- https://github.com/AlistGo/alist/blob/b4d9beb49cba399842a54fcc33bc95a4a09b7bd4/server/handles/fsmanage.go#L165-L166[WEB]
- https://github.com/AlistGo/alist/commit/b188288525b9a35c76535139311e7c036dab057e[WEB]