Threats Tagged 'cve-2026-73509'
View all threats tagged with 'cve-2026-73509'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-73509'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-73509: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in OpenListTeam OpenListCVE-2026-73509 0 OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.go authorizes only the source directory produced by user.JoinPath(req.SrcDir) and validates renameObject.NewName with checkRelativePath, but does not validate attacker-controlled renameObject.SrcName, supplied as src_name, before concatenating it with the authorized path and passing the result to fs.Rename. A user with rename permission can use traversal segments in src_name to make path normalization select a file outside the authorized directory and configured base path, resulting in cross-user file integrity loss, limited availability impact, and file-existence disclosure through success or error responses. This issue is fixed in version 4.2.4. Join the discussion | CVE Database V5 | 08/13/2026, 14:31:05 UTC Added: 08/13/2026, 15:12:13 UTC |
V4: OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal (CVE-2026-73509) 0 OpenList v4 contains a vulnerability in its batch rename API that allows authenticated users with rename permissions to rename files outside their authorized base directory by using path traversal in the source filename parameter. The API validates the destination name but fails to properly validate the source name, enabling directory traversal and unauthorized file renaming. This affects versions prior to 4.2.4 and has a high severity rating with a CVSS score of 7.6. A patch is available to address this issue. Join the discussion | GCVE Database | 07/24/2026, 22:29:08 UTC Added: 07/25/2026, 23:09:17 UTC |
Showing 1 to 2 of 2 results