CVE-2026-101051Low· 3.1▾ SunlitCloudreve before 4.16.1 fails to properly sanitize file paths returned by remote downloaders, allowing authenticated users to create files outside the selected destination directory. Attackers can exploit path traversal sequences in down…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 17.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Cloudreve before 4.16.1 fails to properly sanitize file paths returned by remote downloaders, allowing authenticated users to create files outside the selected destination directory. Attackers can exploit path traversal sequences in downloader metadata to write files to unexpected locations within accessible namespaces.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
GHSA-w8j7-39hp-8x59MediumCloudreve's remote download file paths can escape the selected destination directory
CVE-2026-101056Medium· 5.3Cloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state from a context_hint UUID
CVE-2026-101048Medium· 5.4Cloudreve before 4.17.0 registers the administrative node test endpoints (POST /api/v4/admin/node/test and POST /api/v4/admin/node/test/downloader) without requiring the Admin.Write OAuth scope, unlike the node create/update/delete route…
CVE-2026-79913Medium· 6.5Cloudreve is a self-hosted file management and sharing system
CVE-2026-77633High· 7.1Cloudreve is a self-hosted file management and sharing system
CVE-2026-77637Low· 3.8Cloudreve is a self-hosted file management and sharing system