PT-2026-60181 · Cloudreve · Cloudreve
CVE-2026-54562
·
Published
2026-07-15
·
Updated
2026-07-30
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cloudreve versions prior to 4.16.1
Description
The remote download workflow allows non-admin users with remote download permissions to fetch internal-only URLs. This occurs because the system accepts user-supplied URLs at the POST '/api/v4/workflow/download' endpoint and passes them to the downloader without blocking loopback, localhost, IPv6 localhost, or redirect-to-loopback targets. Consequently, an attacker can read the response after the internal content is imported into their own files.
Recommendations
Update to version 4.16.1.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloudreve