---
id: GO-2026-6113
aliases:
  - GHSA-p6ph-3jx2-3337
title: >-
  OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check
  in Bleve Search in github.com/OpenListTeam/OpenList
summary: >-
  OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check
  in Bleve Search in github.com/OpenListTeam/OpenList
severity: none
vendor: OpenListTeam
product: github.com/OpenListTeam/OpenList
ecosystem: go
affected:
  - github.com/OpenListTeam/OpenList
  - github.com/OpenListTeam/OpenList/v3
  - github.com/OpenListTeam/OpenList/v4 < 4.2.4
patched:
  - github.com/OpenListTeam/OpenList/v4 4.2.4
published: '2026-08-18'
updated: '2026-08-18'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GO-2026-6113'
references:
  - url: >-
      https://github.com/OpenListTeam/OpenList/security/advisories/GHSA-p6ph-3jx2-3337
  - url: >-
      https://github.com/OpenListTeam/OpenList/commit/59bd3431408578f420895457554700cc9a52375a
  - url: >-
      https://github.com/OpenListTeam/OpenList/commit/84ecda35aae2bd0020474086e6ddfd3aa2340679
  - url: 'https://github.com/OpenListTeam/OpenList/releases/tag/v4.2.4'
tags:
  - osv
  - go
ingestedAt: '2026-08-18T19:21:37.861Z'
---

## Overview

OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList

## Affected packages

- `github.com/OpenListTeam/OpenList`
- `github.com/OpenListTeam/OpenList/v3`
- `github.com/OpenListTeam/OpenList/v4 < 4.2.4`

## Remediation

Upgrade to a patched release:

- `github.com/OpenListTeam/OpenList/v4 4.2.4`
