Cloudreve
Cloudreve: vulnerabilities and CVEs
Cloudreve has 17 published vulnerabilities, 16 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs17
Last 12 months16
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-101056 | Medium (6.9) | 0.19% | — | Sep 27, 2026 | Cloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state from a context_hint UUID. Attackers who previously had valid share access can replay the cached hint to generate signed file… |
| CVE-2026-101051 | Low (2.3) | 0.22% | — | Sep 27, 2026 | Cloudreve before 4.16.1 fails to properly sanitize file paths returned by remote downloaders, allowing authenticated users to create files outside the selected destination directory. Attackers can exploit path traversal… |
| CVE-2026-101048 | Medium (5.3) | 0.19% | — | Sep 27, 2026 | Cloudreve before 4.17.0 registers the administrative node test endpoints (POST /api/v4/admin/node/test and POST /api/v4/admin/node/test/downloader) without requiring the Admin.Write OAuth scope, unlike the node… |
| CVE-2026-79913 | Medium (6.5) | 0.40% | — | Sep 22, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, the ValidateExternalURL server-side request forgery guard in pkg/request/ssrf.go passes resolved addresses to checkIP without decoding… |
| CVE-2026-77637 | Low (3.8) | 0.33% | — | Sep 22, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, tool.GET("wopi") and tool.POST("mail") in routers/router.go inherit ScopeAdminRead but omit the RequiredScopes(types.ScopeAdminWrite)… |
| CVE-2026-77633 | High (7.1) | 0.37% | — | Sep 22, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, PrepareUpload in pkg/filemanager/fs/dbfs/upload.go checks a stale in-memory user storage value through validateUserCapacity and later… |
| CVE-2026-62323 | Medium (6.3) | 0.31% | — | Jul 31, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the session-id prefix of a WOPI access token and does not enforce the requested viewer action, allowing a… |
| CVE-2026-55502 | High (7.1) | 0.34% | — | Jul 31, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even though GetOauthRedirectService persists caller-supplied OneDrive… |
| CVE-2026-55499 | Medium (4.3) | 0.33% | — | Jul 31, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscription resolves the share root to the owner’s parent folder and subscribes to that folder topic,… |
| CVE-2026-55497 | Medium (6.5) | 0.53% | — | Jul 31, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed file size but do not limit decoded pixel dimensions, allowing an… |
| CVE-2026-55496 | Medium (4.3) | 0.36% | — | Jul 31, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActive without adding a StatusActive predicate and serializes matches at RedactLevelUser, allowing any… |
| CVE-2026-55495 | Medium (4.3) | 0.38% | — | Jul 31, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-WOPI-SuggestedTarget to URI.JoinRaw as a path rather than a filename, allowing slash and dot-dot… |
| CVE-2026-54563 | High (7.1) | 0.32% | — | Jul 15, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, a Cloudreve WebDAV account rooted at a configured folder can send paths such as /dav/%2e%2e/outside.txt because stripPrefix in… |
| CVE-2026-54562 | Medium (6.5) | 0.40% | — | Jul 15, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, Cloudreve's remote download workflow accepts user-supplied URLs at POST /api/v4/workflow/download and passes them to the configured… |
| CVE-2026-54560 | High (7.6) | 0.46% | — | Jul 15, 2026 | Cloudreve is a self-hosted file management and sharing system. From 4.12.0 until 4.16.1, Cloudreve's OAuth access tokens are issued without the OAuth client_id claim, so the JWT verifier does not load token scopes into… |
| CVE-2026-25726 | Critical (9.8) | 0.50% | — | Apr 3, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to version 4.13.0, the application uses the weak pseudo-random number generator math/rand seeded with time.Now().UnixNano() to generate critical… |
| CVE-2022-32167 | Medium (5.4) | 0.54% | — | Sep 20, 2022 | Cloudreve versions v1.0.0 through v3.5.3 are vulnerable to Stored Cross-Site Scripting (XSS), via the file upload functionality. A low privileged user will be able to share a file with an admin user, which could lead to… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.