{"id":"CVE-2026-69160","aliases":["GHSA-86cx-wwf4-phq4","GO-2026-6109"],"url":"https://o3.security/vulnerability/CVE-2026-69160","summary":"OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API","details":"OpenList a file list program that supports multiple storage. Prior to 4.2.4, the share creation and update checks in server/handles/sharing.go use strings.HasPrefix(requested_path, user.BasePath) without enforcing a directory separator boundary. An authenticated user with CanShare permission and a BasePath such as /base can submit a sibling path such as /base2/secret.txt, create a share for the out-of-scope file, and use the public share download or list handlers to read data outside the assigned directory. This issue is fixed in version 4.2.4.","published":"2026-08-18T18:04:42.070Z","modified":"2026-08-20T03:54:43.601997222Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Go","name":"github.com/OpenListTeam/OpenList/v4","fixedVersion":"4.2.4"}],"fix":{"url":"https://github.com/OpenListTeam/OpenList/commit/59bd3431408578f420895457554700cc9a52375a","label":"OpenListTeam/OpenList@59bd343"},"references":[{"type":"WEB","url":"https://github.com/OpenListTeam/OpenList/releases/tag/v4.2.4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/69xxx/CVE-2026-69160.json"},{"type":"ADVISORY","url":"https://github.com/OpenListTeam/OpenList/security/advisories/GHSA-86cx-wwf4-phq4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69160"},{"type":"FIX","url":"https://github.com/OpenListTeam/OpenList/commit/59bd3431408578f420895457554700cc9a52375a"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-20T03:54:43.601997222Z"}}