github.com/cloudreve/cloudreve/v4 vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-W8J7-39HP-8X59Mediumgithub.com/cloudreve/Cloudreve/v4: Cloudreve's remote download file paths can escape the selected destination directoryGHSA-VX2M-JPXR-XV7WMediumgithub.com/cloudreve/Cloudreve/v4: Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hintGHSA-V6W6-358X-2433Mediumgithub.com/cloudreve/Cloudreve/v4: Cloudreve Admin.Read OAuth tokens can trigger server-side node test requestsCVE-2026-62323Mediumgithub.com/cloudreve/Cloudreve/v4: Cloudreve WOPI view sessions can write files and WOPI access token secret is ignoredCVE-2026-55502Highgithub.com/cloudreve/Cloudreve/v4: Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentialsCVE-2026-55499Mediumgithub.com/cloudreve/Cloudreve/v4: Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and…CVE-2026-55497Mediumgithub.com/cloudreve/Cloudreve/v4: Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the serverCVE-2026-55496Mediumgithub.com/cloudreve/Cloudreve/v4: Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned…CVE-2026-55495Mediumgithub.com/cloudreve/Cloudreve/v4: Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner AccountCVE-2026-54562Mediumgithub.com/cloudreve/Cloudreve/v4: Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responsesCVE-2026-54560Highgithub.com/cloudreve/Cloudreve/v4: Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claimCVE-2026-25726Highgithub.com/cloudreve/Cloudreve/v4: Cloudreve is vulnerable to Account Takeover via Weak Cryptographic Token Generation (Insecure PRNG Seeding)

Stop the waste.
Protect your environment with Kodem.