---
id: CVE-2026-101051
title: >-
  Cloudreve before 4.16.1 fails to properly sanitize file paths returned by
  remote downloaders, allowing authenticated users to create files outside the
  selected destination directory
summary: >-
  Cloudreve before 4.16.1 fails to properly sanitize file paths returned by
  remote downloaders, allowing authenticated users to create files outside the
  selected destination directory. Attackers can exploit path traversal sequences
  in down…
severity: low
cvss: 3.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-22
vendor: cloudreve
product: cloudreve
affected:
  - cloudreve < 4.16.1
published: '2026-09-27'
updated: '2026-09-27'
sourceUpdated: '2026-09-27T18:16:31.620'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101051'
references:
  - url: >-
      https://github.com/cloudreve/cloudreve/security/advisories/GHSA-w8j7-39hp-8x59
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/cloudreve-before-4.16.1-path-traversal-via-remote-download
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-27T17:56:02.210Z'
---

## Overview

Cloudreve before 4.16.1 fails to properly sanitize file paths returned by remote downloaders, allowing authenticated users to create files outside the selected destination directory. Attackers can exploit path traversal sequences in downloader metadata to write files to unexpected locations within accessible namespaces.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
