GO-2026-6289None▾ SunlitCloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve
github.com/cloudreve/Cloudrevegithub.com/cloudreve/Cloudreve/v3github.com/cloudreve/Cloudreve/v4Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
GO-2026-6287NoneCloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/…
GO-2026-6106NoneCloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve
GHSA-w8j7-39hp-8x59MediumCloudreve's remote download file paths can escape the selected destination directory
CVE-2026-54563High· 7.1Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root
GHSA-vx2m-jpxr-xv7wMedium· 5.3Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint
GHSA-v6w6-358x-2433Medium· 5.4Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests