PatchSiren

OpenListTeam CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH OpenListTeam CVE published 2026-08-13

CVE-2026-73509

A vulnerability in OpenList's file list program allows an authenticated user with rename permission to manipulate file paths, potentially leading to cross-user file integrity loss, limited availability impact, and file-existence disclosure. The issue is fixed in version 4.2.4. This vulnerability affects OpenList installations where multiple users have rename permissions, and defenders should assess exposu [truncated]