Executive brief
Cleanuparr is a tool used to automate the management and deletion of unwanted files in media management software like Sonarr and Radarr. A security flaw allows a malicious website to steal a user's permanent API key if they visit the site while Cleanuparr is running on their local network. This could allow an attacker to take full control of the application, access sensitive configuration data, and manage files remotely from anywhere on the internet.
Technical details
Cleanuparr (prior to v2.9.10) implements a global CORS policy that reflects any request 'Origin' and combines it with 'AllowCredentials(true)'. When the 'DisableAuthForLocalAddresses' setting is enabled, the application uses 'TrustedNetworkAuthenticationHandler' to authenticate requests based solely on the source IP address. An attacker can exploit this by tricking an authenticated user (on a trusted IP) into visiting a malicious webpage; the webpage can then perform cross-origin requests to the Cleanuparr API. Because the CORS policy is overly permissive, the browser allows the malicious script to read the authenticated responses, including the admin's permanent API key from the '/api/account/api-key' endpoint.
Affected products
- Cleanuparr Cleanuparr <= 2.9.9
Timeline
- 2026-04-27: advisory: GitHub Security Advisory published
- 2026-05-12: disclosed: CVE-2026-44184 published
- 2026-05-12: patched: Fixed in version 2.9.10