CVE-2024-48747: Alist Project Alist
Medium severity, CVSS 6.8. EPSS: 1% chance of exploitation in the next 30 days.
An issue in alist-tvbox v1.7.1 allows a remote attacker to execute arbitrary code via the /atv-cli file.
Affected products
- Alist Project Alist: version 1.7.1 only
Published 2024-11-21. Last modified 2026-06-17.