AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-25160.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSCRITICAL / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 08, 2026

Disclosure summary

### Summary The application disables TLS certificate verification by default for all outgoing storage driver communications, making the system vulnerable to Man-in-the-Middle (MitM) attacks. This enables the complete decryption, theft, and manipulation of all data transmitted during storage operations, severely compromising the confidentiality and integrity of user data. ### Details Certificate verification is disabled by default for all storage driver communications. The `TlsInsecureSkipVerify` setting is default to true in the `DefaultConfig()` function in [internal/conf/config.go](https://github.com/AlistGo/alist/blob/b4d9beb49cba399842a54fcc33bc95a4a09b7bd4/internal/conf/config.go#L159). ~~~go func DefaultConfig() *Config { // ... TlsInsecureSkipVerify: true, // ... } ~~~ This vulnerability enables Man-in-the-Middle (MitM) attacks by disabling TLS certificate verification, allowing attackers to intercept and manipulate all storage communications. Attackers can exploit this through network-level attacks like ARP spoofing, rogue Wi-Fi access points, or compromised internal network equipment to redirect traffic to malicious endpoints. Since certificate validation is skipped, the s

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-8jmm-3xwx-w974

Open original source · Updated Oct 08, 2026

Alist has Insecure TLS Config

Source severity: CRITICAL / 0

EcosystemPackageAffected rangeFirst patched
gogithub.com/alist-org/alist/v3< 3.57.03.57.0

Original records & references

PUBLISHED 2026-02-04T13:41:26-05:00
MODIFIED 2026-10-08T09:41:27-04:00
INGESTED 2026-10-08T12:30:44-04:00