VulnSea

github.com/cloudreve/Cloudreve/v4 vulnerabilities

CVEs whose affected-version data names the github.com/cloudreve/Cloudreve/v4 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

15 CVEsRSS

CVE-2026-54563High· 7.1
3w ago

Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root

Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root

Twilightcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.32%via GHSA
GO-2026-6289None
3w ago

Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve

Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve

Sunlitcloudreve · github.com/cloudreve/Cloudrevevia OSV
GO-2026-6287None
3w ago

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/…

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/cloudreve/Cloudreve

Sunlitcloudreve · github.com/cloudreve/Cloudrevevia OSV
GHSA-vx2m-jpxr-xv7wMedium· 5.3
4w ago

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint

Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4via GHSA
GHSA-w8j7-39hp-8x59Medium
4w ago

Cloudreve's remote download file paths can escape the selected destination directory

Cloudreve's remote download file paths can escape the selected destination directory

Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4via GHSA
GO-2026-6106None
1mo ago

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve

Sunlitcloudreve · github.com/cloudreve/Cloudrevevia OSV
CVE-2026-55495Medium· 4.3
1mo ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-WOPI-SuggestedTarget to URI.JoinRaw as a path rather than a filename, allowing slash and dot-dot segments to escape th…

Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.26%via NVD
CVE-2026-55496Medium· 4.3
1mo ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActive without adding a StatusActive predicate and serializes matches at RedactLevelUser, allowing any logged-in user to …

Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.26%via NVD
CVE-2026-55497Medium· 6.5
1mo ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed file size but do not limit decoded pixel dimensions, allowing an authenticated user to subm…

Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.29%via NVD
CVE-2026-55499Medium· 4.3
1mo ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscription resolves the share root to the owner’s parent folder and subscribes to that folder topic, allowing an authentic…

Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.24%via NVD
CVE-2026-55502High· 7.1
1mo ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even though GetOauthRedirectService persists caller-supplied OneDrive secret and app_id value…

Twilightcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.23%via NVD
CVE-2026-62323Medium· 6.3
1mo ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the session-id prefix of a WOPI access token and does not enforce the requested viewer action, allowing a malicious or comp…

Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.17%via NVD
GHSA-v6w6-358x-2433Medium· 5.4
1mo ago

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests

Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4via GHSA
CVE-2026-54560High· 7.6
2mo ago

Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim

Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim

Twilightcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.46%via GHSA
CVE-2026-54562Medium· 6.5
2mo ago

Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses

Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses

Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.40%via GHSA
github.com/cloudreve/Cloudreve/v4 vulnerabilities (CVEs) · VulnSea