Vulnerability Database

363,159

Total vulnerabilities in the database

OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search — github.com/OpenListTeam/OpenList/v4

Exposure of Sensitive Information to an Unauthorized Actor

Summary

An authorization bypass and information disclosure vulnerability exists in the search API of Openlist. Due to a non-separator-aware path check and unfiltered backend counting, a low-privileged user can bypass their assigned BasePath restrictions to discover and access metadata of files residing in unauthorized sibling directories.

Details

This vulnerability stems from two combined logic flaws when the bleve search engine is utilized:

  1. Insecure Path Prefix Validation: In the search handler (server/handles/search.go), the application attempts to restrict search results to the user's allowed namespace using a simple prefix check: strings.HasPrefix(node.Parent, user.BasePath). Because this function is not path-separator aware, a user with a BasePath restricted to /base will successfully pass the authorization check for a completely separate directory named /base2 (since "/base2" starts with "/base").

  2. Unfiltered Total Count Leakage: The bleve backend (internal/search/bleve/search.go) searches the index globally and ignores the req.Parent boundary. Even if the application later successfully filters out unauthorized items from the Content array (e.g., via CanAccess meta password checks), it still returns the raw Total count provided by the search backend. This allows an attacker to perform blind data-enumeration, confirming the existence of sensitive files outside their namespace by observing the Total count.

PoC

Prerequisites:

  1. Log in as an administrator and set the Search Index Mode to bleve. Build the index.
  2. Create two directories at the root level: /base and /base2.
  3. Upload a sensitive file into the unauthorized directory: /base2/secret_financial_report.pdf.
  4. Create a low-privileged test user and strictly set their Base path to /base.

Exploitation Steps:

  1. Authenticate as the newly created low-privileged user.
  2. Send the following HTTP request to the search API:
POST /api/fs/search HTTP/1.1 Host: <your-openlist-host> Authorization: <test-user-token> Content-Type: application/json { "parent": "/", "keywords": "secret", "page": 1, "per_page": 20, "scope": 0 }
  1. Observe the response: Due to the prefix bypass (strings.HasPrefix("/base2", "/base") == true), the metadata for secret_financial_report.pdf will be leaked in the response Content.
    • Alternatively, even if access is further blocked by folder-level passwords, the Total field will return > 0, allowing the attacker to blindly confirm the existence of the keyword "secret" in unauthorized global directories.

<img width="2112" height="1381" alt="image" src="https://github.com/user-attachments/assets/9f8c5e18-8744-4363-8d3f-5e6cf691f061" />

Impact

This is an Information Disclosure and Horizontal/Vertical Privilege Escalation vulnerability. Any authenticated user can enumerate hidden infrastructure, verify the existence of sensitive files (e.g., passwords, internal documents), and extract file metadata across the entire storage namespace, completely defeating the BasePath isolation mechanism.

Remediation Recommendations

  1. Separator-Aware Path Containment: Replace strings.HasPrefix with a robust path containment check. For example: target == base || strings.HasPrefix(target, base + "/"), or use a dedicated utility like utils.IsSubPath().
  2. Backend-Level Filtering: Enforce the path boundary within the bleve query itself (e.g., using indexed parent path hashes) rather than relying solely on post-query API filtering.
  3. Accurate Total Calculation: Compute the Total count only after all authorization and path filters have been applied to the result set.
  • Published: Jul 24, 2026
  • Updated: Jul 25, 2026
  • GHSA: GHSA-p6ph-3jx2-3337
  • Severity: Medium
  • Exploit:
  • CISA KEV:

CVSS v3:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Frequently Asked Questions

A security vulnerability is a weakness in software, hardware, or configuration that can be exploited to compromise confidentiality, integrity, or availability. Many vulnerabilities are tracked as CVEs (Common Vulnerabilities and Exposures), which provide a standardized identifier so teams can coordinate patching, mitigation, and risk assessment across tools and vendors.

CVSS (Common Vulnerability Scoring System) estimates technical severity, but it doesn't automatically equal business risk. Prioritize using context like internet exposure, affected asset criticality, known exploitation (proof-of-concept or in-the-wild), and whether compensating controls exist. A "Medium" CVSS on an exposed, production system can be more urgent than a "Critical" on an isolated, non-production host.

A vulnerability is the underlying weakness. An exploit is the method or code used to take advantage of it. A zero-day is a vulnerability that is unknown to the vendor or has no publicly available fix when attackers begin using it. In practice, risk increases sharply when exploitation becomes reliable or widespread.

Recurring findings usually come from incomplete Asset Discovery, inconsistent patch management, inherited images, and configuration drift. In modern environments, you also need to watch the software supply chain: dependencies, containers, build pipelines, and third-party services can reintroduce the same weakness even after you patch a single host. Unknown or unmanaged assets (often called Shadow IT) are a common reason the same issues resurface.

Use a simple, repeatable triage model: focus first on externally exposed assets, high-value systems (identity, VPN, email, production), vulnerabilities with known exploits, and issues that enable remote code execution or privilege escalation. Then enforce patch SLAs and track progress using consistent metrics so remediation is steady, not reactive.

SynScan combines attack surface monitoring and continuous security auditing to keep your inventory current, flag high-impact vulnerabilities early, and help you turn raw findings into a practical remediation plan.