cloudreve
6 known vulnerabilities in cloudreve, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-101056 CVSS 6.9 medium Cloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state from a context_hint UUID. Attackers who…
- CVE-2026-101051 CVSS 2.3 low Cloudreve before 4.16.1 fails to properly sanitize file paths returned by remote downloaders, allowing authenticated users to create files…
- CVE-2026-101048 CVSS 5.3 medium Cloudreve before 4.17.0 registers the administrative node test endpoints (POST /api/v4/admin/node/test and POST…
- CVE-2026-79913 CVSS 6.5 medium Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, the ValidateExternalURL server-side request forgery guard…
- CVE-2026-77637 CVSS 3.8 low Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, tool.GET("wopi") and tool.POST("mail") in…
- CVE-2026-77633 CVSS 7.1 high Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, PrepareUpload in pkg/filemanager/fs/dbfs/upload.go checks…