Executive brief
Cloudreve is a self-hosted cloud storage platform that manages file storage nodes. Before version 4.17.0, two administrative endpoints for testing node connectivity fail to enforce proper authorization checks, allowing an attacker with limited admin read-only credentials to trigger outbound network requests to arbitrary destinations. This enables server-side request forgery attacks that can probe internal networks, access internal services, or deliver malicious requests to attacker-controlled endpoints.
Technical details
The POST /api/v4/admin/node/test and POST /api/v4/admin/node/test/downloader endpoints execute network operations using attacker-supplied node configuration but enforce only the Admin.Read OAuth scope instead of Admin.Write. An authenticated OAuth client with Admin.Read authorization can submit arbitrary node definitions and trigger TestNodeService.Test() to send requests to attacker-controlled URLs, resulting in blind SSRF. The root cause is incomplete scope enforcement on side-effect-generating endpoints in the admin route group.
Affected products
- Cloudreve Cloudreve before 4.17.0
Timeline
- 2026-07-23: disclosed
- 2026-07-23: patched: Fixed in version 4.17.0