Cloudreve 4.17.0 之前的版本中,管理员节点测试端点(POST /api/v4/admin/node/test 和 POST /api/v4/admin/node/test/downloader)在注册时未要求 Admin.Write OAuth 权限范围,而节点创建/更新/删除路由则有此要求。因此,一个仅被授予 Admin.Read 范围并经管理员授权的 OAuth 客户端,可以提交攻击者控制的节点定义,从而促使 Cloudreve 服务器向任意 URL 发起出站请求。这导致盲服务端请求伪造(Bli
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101056 | 5.3 MEDIUM | Cloudreve before 4.16.1 Authentication Bypass via Cached Context Hint |
| CVE-2026-101051 | 3.1 LOW | Cloudreve before 4.16.1 Path Traversal via Remote Download |
No comments yet