CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-p6ph-3jx2-3337: OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search

mediumCVSS 4.3
Summary An authorization bypass and information disclosure vulnerability exists in the search API of Openlist. Due to a non-separator-aware path check and unfiltered backend counting, a low-privileged user can bypass their assigned BasePath restrictions to discover and access metadata of files residing in unauthorized sibling directories. Details This vulnerability stems from two combined logic flaws when the bleve search engine is utilized: 1. Insecure Path Prefix Validation: In the search handler (server/handles/search.go), the application attempts to restrict search results to the user's allowed namespace using a simple prefix check: strings.HasPrefix(node.Parent, user.BasePath). Because this function is not path-separator aware, a user with a BasePath restricted to /base will successfully pass the authorization check for a completely separate directory named /base2 (since "/base2" starts with "/base"). 2. Unfiltered Total Count Leakage: The bleve backend (internal/search/bleve/search.go) searches the index globally and ignores the req.Parent boundary. Even if the application later successfully filters out unauthorized items from the Content array (e.g., via CanAccess meta password checks), it still returns the raw Total count provided by the search backend. This allows an attacker to perform blind data-enumeration, confirming the existence of sensitive files outside their namespace by observing the Total count. PoC Prerequisites: 1. Log in as an administrator and set the Search Index Mode to bleve. Build the index. 2. Create two directories at the root level: /base and /base2. 3. Upload a sensitive file into the unauthorized directory: /base2/secret_financial_report.pdf. 4. Create a low-privileged test user and strictly set their Base path to /base. Exploitation Steps: 1. Authenticate as the newly created low-privileged user. 2. Send the following HTTP request to the search API: POST /api/fs/search HTTP/1.1 Host: <your-openlist-host> Authorization: <test-u

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
medium — CVSS 4.3
Published
2026-07-24
Last updated
2026-07-24
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-p6ph-3jx2-3337

More from GitHub Security Advisories