CVE-2026-101051: Cloudreve before 4.16.1 Path Traversal via Remote Download
Cloudreve before 4.16.1 fails to properly sanitize file paths returned by remote downloaders, allowing authenticated users to create files outside the selected destination directory. Attackers can exploit path traversal sequences in downloader metadata to write files to unexpected locations within accessible namespaces.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated and able to use a remote downloader that returns attacker-controlled file path metadata. The resulting writes are limited to locations within namespaces accessible to that user.
Is user interaction required?
No. The vector indicates no user interaction is required, but exploitation has high attack complexity and requires low-level authenticated privileges.
What versions are affected?
Cloudreve versions before 4.16.1 are affected. Upgrading to 4.16.1 or later addresses the affected version range described.
What is the impact of successful exploitation?
An authenticated attacker can create files outside the destination directory selected for a remote download. The stated impact is integrity-only: files may be written to unexpected accessible locations, with no confidentiality or availability impact indicated.