VDB

CVE-2026-25060

CVE-2026-25060 PUBLISHED CVSS 8.100000381469727 HIGH

OpenList Frontend is a UI component for OpenList. Prior to 4.1.10, certificate verification is disabled by default for all storage driver communications. The TlsInsecureSkipVerify setting is default to true in the DefaultConfig() function in internal/conf/config.go. This vulnerability enables Man-in-the-Middle (MitM) attacks by disabling TLS certificate verification, allowing attackers to intercept and manipulate all storage communications. Attackers can exploit this through network-level attacks like ARP spoofing, rogue Wi-Fi access points, or compromised internal network equipment to redirect traffic to malicious endpoints. Since certificate validation is skipped, the system will unknowingly establish encrypted connections with attacker-controlled servers, enabling full decryption, data theft, and manipulation of all storage operations without triggering any security warnings. This vulnerability is fixed in 4.1.10.

EPSS 0.01% · 1.8th percentile

Risk Scores

CVSS v3.1
8.100000381469727
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.01%
1.8th percentile

Affected Products

VendorProductVersions
oplistopenlist0, 0
OpenListTeamOpenList*, *
github.comOpenListTeam/OpenList/v40, 0

Timeline

  • Feb 2, 2026 CVE Published
  • Feb 2, 2026 PoC Published
  • Feb 2, 2026 PoC Published
  • Feb 3, 2026 CVE Updated
  • Feb 3, 2026 EPSS Score
  • Feb 5, 2026 EPSS Score
  • Feb 5, 2026 Security Advisory
  • Feb 7, 2026 EPSS Score
  • Feb 10, 2026 EPSS Score
  • Feb 12, 2026 EPSS Score
  • Feb 14, 2026 EPSS Score
  • Feb 16, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›