Junglewise Threat Intelligence

GO-2026-6287 - Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/clo

Severity: info · Published 2026-08-25

Technologies: github.com/cloudreve/Cloudreve/v4 (Go), github.com/cloudreve/Cloudreve/v3 (Go), github.com/cloudreve/Cloudreve (Go). Vendors: Go.

Executive brief

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/cloudreve/Cloudreve

Affected products

  • Go github.com/cloudreve/Cloudreve/v4
  • Go github.com/cloudreve/Cloudreve/v3
  • Go github.com/cloudreve/Cloudreve

Related threats