Executive brief
Cloudreve is a file management system that allows users to store and download files. A vulnerability in the remote download feature allows certain users to trick the server into accessing internal network services or local files that should be private. This could lead to the exposure of sensitive internal data, administrative panels, or system metadata.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in Cloudreve's remote download workflow at the `/api/v4/workflow/download` endpoint. The application fails to validate user-supplied URLs before passing them to the downloader (such as Aria2), allowing requests to loopback addresses (127.0.0.1, localhost, [::1]) and internal network ranges. An authenticated attacker with `GroupPermissionRemoteDownload` enabled can fetch content from internal-only HTTP services and subsequently read the response body after it is imported into their Cloudreve file library. The vulnerability also follows redirects to internal targets. A patch is available in version 4.0.0-20260606025411-aaebf317a78f (released as part of 4.16.1).
Affected products
- Cloudreve Cloudreve/v3 <= 3.0.0-20250225100611-da4e44b77af4
- Cloudreve Cloudreve/v4 < 4.0.0-20260606025411-aaebf317a78f
Timeline
- 2026-07-15: advisory: NVD published date
- 2026-07-20: disclosed: GitHub Advisory published