在 Cloudreve 4.16.1 之前的版本中,系统未能正确清理远程下载器返回的文件路径,导致经过身份验证的用户可以创建位于选定目标目录之外的文件。攻击者可通过在下载器元数据中利用路径遍历序列,将文件写入可访问命名空间内意料之外的位置。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101048 | 5.4 MEDIUM | Cloudreve before 4.17.0 SSRF via Admin.Read OAuth scope |
| CVE-2026-101056 | 5.3 MEDIUM | Cloudreve before 4.16.1 Authentication Bypass via Cached Context Hint |
No comments yet