CVE-2026-55499Medium· 4.3▾ SunlitCloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscription resolves the share root to the owner’s parent folder and subscribes to that folder topic, allowing an authentic…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 31.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscription resolves the share root to the owner’s parent folder and subscribes to that folder topic, allowing an authenticated share recipient to receive names, paths, rename targets, event types, and hashed identifiers for unshared sibling files and folders. This issue is fixed in version 4.17.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/cloudreve/Cloudreve/v4 < 4.0.0-20260613030215-0b00dd308f13github.com/cloudreve/Cloudreve/v3 <= 3.0.0-20250225100611-da4e44b77af4Patched in:
github.com/cloudreve/Cloudreve/v4 4.0.0-20260613030215-0b00dd308f13Connected by shared product, vendor, weakness, or advisory.
GHSA-v6w6-358x-2433Medium· 5.4Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
CVE-2026-55502High· 7.1Cloudreve is a self-hosted file management and sharing system
CVE-2026-62323Medium· 6.3Cloudreve is a self-hosted file management and sharing system
CVE-2026-54563High· 7.1Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root
GHSA-vx2m-jpxr-xv7wMedium· 5.3Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint
CVE-2026-55495Medium· 4.3Cloudreve is a self-hosted file management and sharing system