github.com/alist-org/alist/v3 vulnerabilities
CVEs whose affected-version data names the github.com/alist-org/alist/v3 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-25161High· 8.8Alist vulnerable to Path Traversal in multiple file operation handlers
Alist vulnerable to Path Traversal in multiple file operation handlers
▾ Twilightalist-org · github.com/alist-org/alist/v3EPSS 0.81%via GHSA
CVE-2026-25160Critical· 9.1Alist has Insecure TLS Config
Alist has Insecure TLS Config
▾ Midnightalist-org · github.com/alist-org/alist/v3EPSS 0.25%via GHSA