Cloudreve 4.16.1 版本之前的版本在从 context_hint UUID 恢复缓存的导航器状态时,未能重新验证分享访问权限。攻击者如果此前拥有有效的分享访问权限,可以在分享被删除、过期或剩余下载次数降至零后的最多 300 秒内,通过重放该缓存的提示(hint),重新生成已分享文件的签名下载链接。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101048 | 5.4 MEDIUM | Cloudreve before 4.17.0 SSRF via Admin.Read OAuth scope |
| CVE-2026-101051 | 3.1 LOW | Cloudreve before 4.16.1 Path Traversal via Remote Download |
No comments yet