📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Patch & vulnerability status

Alist 3.40.0

Latest tracked version 3.40.0. Release status, tracked CVEs, and automated cross-platform patching for Alist.

PlatformLatest versionCVEs trackedLast checked
Windows3.40.072024-12-06

Known vulnerabilities (CVEs) in Alist

Lavawall tracks 7 published CVEs affecting Alist, and deploys the versions that fix them automatically across your fleet.

CVEPublishedSeverityDetailsVector
CVE-2024-470672024-09-30 16:15:09MEDIUM (6)AList is a file list program that supports multiple storages. AList contains a reflected cross-site scripting vulnerability in helper.go. The endpoint /i/:link_name takes in a user-provided value and reflects it back in the response. The endpoint returns an application/xml response, opening it up to HTML tags via XHTML and thus leading to a XSS vulnerability. This vulnerability is fixed in 3.29.0.NETWORK
CVE-2023-334982023-06-07 14:15:10HIGH (9)alist <=3.16.3 is vulnerable to Incorrect Access Control. Low privilege accounts can upload any file.NETWORK
CVE-2023-317262023-05-23 22:15:10HIGH (8)AList 3.15.1 is vulnerable to Incorrect Access Control, which can be exploited by attackers to obtain sensitive information.NETWORK
CVE-2022-459702022-12-12 14:15:11MEDIUM (5)Alist v3.5.1 is vulnerable to Cross Site Scripting (XSS) via the bulletin board.NETWORK
CVE-2022-459692022-12-15 23:15:10CRITICAL (10)Alist v3.4.0 is vulnerable to Directory Traversal,NETWORK
CVE-2022-459682022-12-12 14:15:11HIGH (9)Alist v3.4.0 is vulnerable to File Upload. A user with only file upload permission can upload any file to any folder (even a password protected one).NETWORK
CVE-2022-265332022-03-12 01:15:36MEDIUM (6)Alist v2.1.0 and below was discovered to contain a cross-site scripting (XSS) vulnerability via /i/:data/ipa.plist.NETWORK

Why keeping Alist patched matters

Unpatched third-party applications are one of the most common ways attackers get in: 57% of breached MSP clients and 32% of ransomware cases trace back to a missing patch. Every Alist release that fixes a security bug is public, so attackers see it too, and an out-of-date install becomes a documented way in. Tracking the installed version on every machine and closing the gap quickly is what turns a disclosed CVE into a non-event.

How Lavawall® patches Alist

Lavawall® watches Alist releases and CVEs continuously, ranks each update by risk, and deploys it across your whole fleet, Windows, macOS, and Linux, from a single agent, independently of your RMM. You get one place to see which machines are behind on Alist, one policy to bring them current, and timestamped evidence for audits.

Frequently asked questions

What is the latest version of Alist?
Lavawall tracks Alist at version 3.40.0 (last checked 2024-12-06). New releases are monitored continuously and can be deployed automatically across your fleet.
Does Alist have known security vulnerabilities (CVEs)?
Lavawall tracks 7 CVEs for Alist and remediates them automatically as part of patching.
How do I patch Alist automatically?
Deploy the Lavawall® agent and Alist updates are applied automatically across Windows, macOS, and Linux, risk-ranked and reported, independently of your RMM.

Lavawall® monitors releases and CVEs for Alist through public information and proprietary statistical analysis, and can patch it automatically across your fleet.