CVE-2026-73509 | OpenListTeam OpenList up to 4.2.3 Path Normalization fsbatch.go api/fs/batch_rename src_name path traversal

SecurityVulns

A vulnerability was found in OpenListTeam OpenList up to 4.2.3. It has been rated as critical. Affected is the function api/fs/batch_rename of the file server/handles/fsbatch.go of the component Path Normalization. This manipulation of the argument src_name causes path traversal.

This vulnerability is handled as CVE-2026-73509. The attack can be initiated remotely. There is not any exploit available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More