CVE-2026-25160Disclosure(alistgo / alist)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch alistgo alist systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application disables TLS certificate verification by default for all outgoing storage driver communications, making the system vulnerable to Man-in-the-Middle (MitM) attacks. This enables the complete decryption, theft, and manipulation of all data transmitted during storage operations, severely compromising the confidentiality and integrity of user data. This issue has been patched in version 3.57.0.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • alist

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 3 mentions (2026-02-04); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
alist

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-02-04: 3Mentions · 2026-02-05: 1Mentions · 2026-02-06: 1PoC Mentioned / Linked · 2026-02-04: 1Patch / Workaround · 2026-02-04: 1Patch / Workaround · 2026-02-05: 1Technical Details · 2026-02-04: 3Technical Details · 2026-02-05: 1Technical Details · 2026-02-06: 102-0402-0502-06
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-043
Disclosure3
2026-02-051
Patch1
2026-02-061
Disclosure1
Full discourse5 posts
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-25160: CRITICAL] Alist application prior to version 3.57.0 had a vulnerability bypassing TLS certificate verification, posing risk for Man-in-the-Middle attacks. Update to version 3.57.0 for fix.#cve,CVE-2026-25160,#cybersecurity https://cvefind.com/CVE-2026-25160

    Post summary

    The post highlights a critical TLS bypass vulnerability in Alist before v3.57.0 and recommends updating to the patched version 3.57.0 to mitigate the risk.

    0001070
    583 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    Alist has an insecure TLS config (CVE-2026-25160). This could allow data interception. Review your deployment #Alist #TLS #Security. https://www.pulsepatch.io/posts/cve-2026-25160-alist-insecure-tls-configuration

    Post summary

    Alist's insecure TLS configuration (CVE-2026-25160) may allow data interception; no PoC, exploit, or patch is referenced.

    0000051
    1 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-25160 - Critical Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application disables TLS certificate verification by default for all... https://www.thehackerwire.com/vulnerability/CVE-2026-25160/ https://t.co/A3xTB4nEXf

    Post summary

    CVE-2026-25160 is disclosed as a critical vulnerability in Alist, where TLS certificate verification is disabled by default prior to v3.57.0; no PoC, exploit, or patch details are provided.

    0000084
    113 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-25160: Alist has Insecure TLS Config (C... Alist's disabled TLS cert verification turns every storage operation into a MITM goldmine - trivial to exploit with bas... https://zerodaysignal.com/vulnerability/CVE-2026-25160 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑25160, highlighting Alist’s insecure TLS configuration that permits trivial MITM attacks, and directs readers to a link for further details.

    0000070
    132 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25160 Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application disables TLS certificate verificati… https://www.cve.org/CVERecord?id=CVE-2026-25160

    Post summary

    CVE‑2026‑25160 is a TLS certificate verification bypass in Alist, fixed in version 3.57.0, requiring an upgrade to mitigate the vulnerability.

    00000202
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appalistgoalist---

Explore more