Server-Side Request Forgery Vulnerability in Cloudreve by Cloudreve
CVE-2026-101048
5.3MEDIUM
What is CVE-2026-101048?
An identified vulnerability in Cloudreve versions prior to 4.17.0 allows unauthorized submissions of node definitions through the administrative test endpoints without proper OAuth scope verification. This weakness permits attackers, with only the Admin.Read scope, to craft malicious requests that can lead to server-side request forgery. As a result, this may enable attackers to probe internal services, execute outbound requests to arbitrary URLs, and exploit the Cloudreve environment for unauthorized actions and data leakage.
Affected Version(s)
cloudreve 0 < 4.17.0
cloudreve 4.17.0
