VYPR
High severity8.8NVD Advisory· Published Dec 12, 2022· Updated Jun 17, 2026

CVE-2022-45968

CVE-2022-45968

Description

Alist v3.4.0 is vulnerable to File Upload. A user with only file upload permission can upload any file to any folder (even a password protected one).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/alist-org/alist/v3Go
< 3.5.13.5.1

Affected products

3

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.