Medium severity6.5NVD Advisory· Published Jul 15, 2026· Updated Jul 15, 2026
CVE-2026-54562
CVE-2026-54562
Description
Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, Cloudreve's remote download workflow accepts user-supplied URLs at POST /api/v4/workflow/download and passes them to the configured downloader without blocking loopback, localhost, IPv6 localhost, or redirect-to-loopback targets, allowing a non-admin user with remote download permission to fetch internal-only URLs and read the response after it is imported into the user's own files. This issue is fixed in version 4.16.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/cloudreve/Cloudreve/v4Go | < 4.0.0-20260606025411-aaebf317a78f | 4.0.0-20260606025411-aaebf317a78f |
github.com/cloudreve/Cloudreve/v3Go | <= 3.0.0-20250225100611-da4e44b77af4 | — |
Affected products
2- osv-coordsRange: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-x756-g4x3-c64mghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-54562ghsaADVISORY
- github.com/cloudreve/cloudreve/commit/aaebf317a78f2413d74afd66c21a1f3143711312nvdWEB
- github.com/cloudreve/cloudreve/releases/tag/4.16.1nvdWEB
- github.com/cloudreve/cloudreve/security/advisories/GHSA-x756-g4x3-c64mnvdWEB
News mentions
0No linked articles in our index yet.