Executive brief
Cloudreve, a self-hosted file management and sharing system, contains a security flaw in how it generates its internal master keys. An attacker can mathematically predict these keys by analyzing publicly available information, such as when the administrator's account was created. If successful, an attacker can gain full control over the system, access all stored files, and impersonate any user, including administrators.
Technical details
Cloudreve prior to version 4.13.0 uses the insecure 'math/rand' PRNG seeded with 'time.Now().UnixNano()' to generate critical secrets like 'secret_key' and 'hash_id_salt' during initial setup. Because the seed is based on a predictable timestamp, an attacker can use public API endpoints to determine the administrator's account creation time and narrow the search space for the seed. By brute-forcing the seed (demonstrated to take less than 3 hours on consumer hardware), an attacker can recover the 'secret_key' and forge valid JSON Web Tokens (JWTs). This leads to unauthenticated administrative access and full system compromise. The vulnerability persists in newer versions if the instance was originally initialized with a version prior to 4.10.0.
Affected products
- Cloudreve Cloudreve < 4.13.0
Timeline
- 2026-02-05: patched: Version 4.13.0 released with security fix.
- 2026-03-31: advisory: Vendor security advisory published.
- 2026-04-03: disclosed: CVE-2026-25726 published.