Path Traversal Vulnerability in Cloudreve Product by Cloudreve
CVE-2026-101051

2.3LOW

Key Information:

Vendor

Cloudreve

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-101051?

In versions of Cloudreve before 4.16.1, a path traversal vulnerability exists that allows authenticated users to manipulate file paths returned by remote downloaders. By exploiting this flaw, attackers can craft path traversal sequences in downloader metadata, potentially leading to unintended file writes beyond the designated directory. This vulnerability poses significant risks related to unauthorized file access and data exfiltration.

Affected Version(s)

cloudreve 0 < 4.16.1

cloudreve 4.16.1

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

jinhao-huang
.