VYPR
Medium severity6.5NVD Advisory· Published Jul 15, 2026· Updated Jul 15, 2026

CVE-2026-54562

CVE-2026-54562

Description

Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, Cloudreve's remote download workflow accepts user-supplied URLs at POST /api/v4/workflow/download and passes them to the configured downloader without blocking loopback, localhost, IPv6 localhost, or redirect-to-loopback targets, allowing a non-admin user with remote download permission to fetch internal-only URLs and read the response after it is imported into the user's own files. This issue is fixed in version 4.16.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/cloudreve/Cloudreve/v4Go
< 4.0.0-20260606025411-aaebf317a78f4.0.0-20260606025411-aaebf317a78f
github.com/cloudreve/Cloudreve/v3Go
<= 3.0.0-20250225100611-da4e44b77af4

Affected products

2

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.