Executive brief
Cleanuparr, a tool used to manage and clean up media files in automated home server environments, contains a critical security flaw that allows anyone on the internet to log in as an administrator. By sending a specially crafted network request that mimics a local connection, an attacker can bypass authentication entirely. This gives the attacker full control over the application, including access to sensitive API keys and credentials for connected services like Sonarr, Radarr, and Plex.
Technical details
Cleanuparr (prior to v2.9.10) is vulnerable to an authentication bypass (CWE-290) in its TrustedNetworkAuthenticationHandler. The ResolveClientIp method incorrectly parses the leftmost entry of the X-Forwarded-For header as the source IP. Because this header is append-only, the leftmost value is entirely attacker-controlled. If the application is deployed behind a reverse proxy with 'TrustForwardedHeaders' enabled, an unauthenticated remote attacker can provide a spoofed internal IP (e.g., 127.0.0.1 or a 10.0.0.0/8 address) to satisfy the 'IsLocalAddress' check. This results in the attacker being granted full administrative access, allowing for the exfiltration of API keys and service secrets. The issue is fixed in version 2.9.10.
Affected products
- Cleanuparr Cleanuparr <= 2.9.9
Timeline
- 2026-04-27: advisory: GitHub Security Advisory published
- 2026-05-12: disclosed: CVE-2026-44183 published to NVD
- 2026-05-12: patched: Fix released in version 2.9.10