Patch & vulnerability status
Alist 3.40.0
Latest tracked version 3.40.0. Release status, tracked CVEs, and automated cross-platform patching for Alist.
| Platform | Latest version | CVEs tracked | Last checked |
|---|---|---|---|
| Windows | 3.40.0 | 7 | 2024-12-06 |
Known vulnerabilities (CVEs) in Alist
Lavawall tracks 7 published CVEs affecting Alist, and deploys the versions that fix them automatically across your fleet.
| CVE | Published | Severity | Details | Vector |
|---|---|---|---|---|
| CVE-2024-47067 | 2024-09-30 16:15:09 | MEDIUM (6) | AList is a file list program that supports multiple storages. AList contains a reflected cross-site scripting vulnerability in helper.go. The endpoint /i/:link_name takes in a user-provided value and reflects it back in the response. The endpoint returns an application/xml response, opening it up to HTML tags via XHTML and thus leading to a XSS vulnerability. This vulnerability is fixed in 3.29.0. | NETWORK |
| CVE-2023-33498 | 2023-06-07 14:15:10 | HIGH (9) | alist <=3.16.3 is vulnerable to Incorrect Access Control. Low privilege accounts can upload any file. | NETWORK |
| CVE-2023-31726 | 2023-05-23 22:15:10 | HIGH (8) | AList 3.15.1 is vulnerable to Incorrect Access Control, which can be exploited by attackers to obtain sensitive information. | NETWORK |
| CVE-2022-45970 | 2022-12-12 14:15:11 | MEDIUM (5) | Alist v3.5.1 is vulnerable to Cross Site Scripting (XSS) via the bulletin board. | NETWORK |
| CVE-2022-45969 | 2022-12-15 23:15:10 | CRITICAL (10) | Alist v3.4.0 is vulnerable to Directory Traversal, | NETWORK |
| CVE-2022-45968 | 2022-12-12 14:15:11 | HIGH (9) | Alist v3.4.0 is vulnerable to File Upload. A user with only file upload permission can upload any file to any folder (even a password protected one). | NETWORK |
| CVE-2022-26533 | 2022-03-12 01:15:36 | MEDIUM (6) | Alist v2.1.0 and below was discovered to contain a cross-site scripting (XSS) vulnerability via /i/:data/ipa.plist. | NETWORK |
Why keeping Alist patched matters
Unpatched third-party applications are one of the most common ways attackers get in: 57% of breached MSP clients and 32% of ransomware cases trace back to a missing patch. Every Alist release that fixes a security bug is public, so attackers see it too, and an out-of-date install becomes a documented way in. Tracking the installed version on every machine and closing the gap quickly is what turns a disclosed CVE into a non-event.
How Lavawall® patches Alist
Lavawall® watches Alist releases and CVEs continuously, ranks each update by risk, and deploys it across your whole fleet, Windows, macOS, and Linux, from a single agent, independently of your RMM. You get one place to see which machines are behind on Alist, one policy to bring them current, and timestamped evidence for audits.
Frequently asked questions
Lavawall tracks Alist at version 3.40.0 (last checked 2024-12-06). New releases are monitored continuously and can be deployed automatically across your fleet.
Lavawall tracks 7 CVEs for Alist and remediates them automatically as part of patching.
Deploy the Lavawall® agent and Alist updates are applied automatically across Windows, macOS, and Linux, risk-ranked and reported, independently of your RMM.
Lavawall® monitors releases and CVEs for Alist through public information and proprietary statistical analysis, and can patch it automatically across your fleet.