Skip to content

alist

v3.61.0 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 2d File Storage & Sync
โœ“ No known CVEs patched
Read the diff โ†’ Tool health โ†’ What is this tool? โ†’
This release patches 2 known CVEs

Topics

file-server gin go onedrive solidjs webdav

Summary

AI summary

Broad release touches ๐Ÿž Bug Fixes, ๐Ÿš€ Features, https://github.com/AlistGo/alist/commit/fc26c3d8, and fc26c.

Full changelog

ย ย ย ๐Ÿš€ Features

  • Add GuangYaPan offline download ย -ย  by @okatu-loli in https://github.com/AlistGo/alist/issues/9505 (fc26c)
  • 139-share:
    • Support mounting and HLS playback ย -ย  by ** 139ไบ‘็›˜ๅˆ†ไบซ้“พๆŽฅๅœจM3U8ไธญไฝฟ็”จ็›ธๅฏนTS่ทฏๅพ„๏ผŒๅฏผ่‡ดไปฃ็†่ฏทๆฑ‚ๆ— ๆณ•ๆญฃๅธธ่งฃๆžใ€‚ๆญคๅค–๏ผŒAListไธ‹่ฝฝๅ™จไผšไธฅๆ ผๆ ก้ชŒๆ–‡ไปถๅ…ƒๆ•ฐๆฎไธŽๅฎž้™…ๆต็š„ๅคงๅฐไธ€่‡ดๆ€ง๏ผŒๅฏผ่‡ดๅŠจๆ€็”Ÿๆˆ็š„M3U8ๅ› ้•ฟๅบฆไธๅŒน้…่งฆๅ‘416ๆˆ–EOF้”™่ฏฏใ€‚ๆˆ‘ไปฌ้‡‡็”จไบ†1MBๅกซๅ……ๆŠ€ๆœฏไปฅๅ…ผๅฎนAList็š„ไธฅๆ ผๆ ก้ชŒ๏ผŒไธ”1MB่ถณไปฅๅฎน็บณ็ปๅคงๅคšๆ•ฐM3U8ๆ–‡ไปถ่€Œไธๅฝฑๅ“ๆ€ง่ƒฝใ€‚ Changes: alist/drivers/139/types.go - Added ShareCatalog and ShareContent structs for API response mapping ** [( ๆ”ฏๆŒๅˆ†ไบซ)](https://github.com/AlistGo/alist/commit/ ๆ”ฏๆŒๅˆ†ไบซ้“พๆŽฅๆŒ‚่ฝฝไธŽๆ’ญๆ”พ Root cause: 139 Cloud share links use relative TS paths in M3U8 playlists which cannot be resolved by proxied clients. Additionally, AList's downloader enforces strict metadata-to-stream size validation, leading to 416 (Range) or EOF errors when serving dynamic M3U8 content. We implemented a 1MB padding technique to ensure compatibility with AList's strict size checks; 1MB is sufficient for almost all M3U8 files without impacting performance. )
  • api:
    • Add virtual_path field on fs/list and fs/get responses ย -ย  by @okatu-loli (e36c6)
  • lark:
    • Add export tools API ย -ย  by @okatu-loli in https://github.com/AlistGo/alist/issues/9511 (d509a)
  • settings:
    • Add frontend sort memory switch ย -ย  by @okatu-loli (cbeb0)
    • Add preview_settings for per-extension preview management ย -ย  by @okatu-loli (1db7a)

ย ย ย ๐Ÿž Bug Fixes

  • V-002 security vulnerability ย -ย  by @orbisai0security (e35ab)
  • Support all pagination mode ย -ย  by @okatu-loli in https://github.com/AlistGo/alist/issues/9512 (0fa86)
  • CVE-2026-34986 security vulnerability ย -ย  by @orbisai0security (02c09)
  • 139-share:
    • Fix modification time parsing ย -ย  by 45daac9e [( ไฟฎๅคๅˆ†ไบซ)](https://github.com/AlistGo/alist/commit/ ไฟฎๅคๅˆ†ไบซๆจกๅผไธ‹็š„ไฟฎๆ”นๆ—ถ้—ด่งฃๆž)
  • guangyapan:
    • Allow user input folder path in driver root path ย -ย  by @abandonstudy (dba5c)
    • Expose sorting options ย -ย  by @okatu-loli (4a23e)
    • Resolve offline root folder lookup ย -ย  by @okatu-loli in https://github.com/AlistGo/alist/issues/9516 (de569)
  • lanzou:
    • Handle acw_sc__v2 anti-crawler challenge on all requests ย -ย  by @okatu-loli in https://github.com/AlistGo/alist/issues/9548 (d0cec)
  • mcp:
    • Initialize task manager so async fs operations don't panic ย -ย  by @okatu-loli and Claude Opus 4.7 (69464)
  • meta:
    • Expire missing meta cache ย -ย  by @okatu-loli in https://github.com/AlistGo/alist/issues/9504 (f4459)
  • net:
    • Synchronize Buf.Close with Write/Read to prevent nil-pointer panic ย -ย  by @okatu-loli and Claude Opus 4.7 (0e9f8)
  • storage:
    • Clear list cache after storage updates ย -ย  by @okatu-loli (ffbbe)
ย ย ย ย View changes on GitHub

Security Fixes

  • V-002 security vulnerability fixed (commit e35abf51)
  • CVE-2026-34986 security vulnerability fixed (commit 02c09a77)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track alist

Get notified when new releases ship.

Sign up free

About alist

A file list/WebDAV program that supports multiple storages, powered by Gin and Solidjs. / ไธ€ไธชๆ”ฏๆŒๅคšๅญ˜ๅ‚จ็š„ๆ–‡ไปถๅˆ—่กจ/WebDAV็จ‹ๅบ๏ผŒไฝฟ็”จ Gin ๅ’Œ Solidjsใ€‚

All releases โ†’

Related context

Beta — feedback welcome: [email protected]