Path Traversal Vulnerability in Cloudreve Product by Cloudreve
CVE-2026-101051
2.3LOW
What is CVE-2026-101051?
In versions of Cloudreve before 4.16.1, a path traversal vulnerability exists that allows authenticated users to manipulate file paths returned by remote downloaders. By exploiting this flaw, attackers can craft path traversal sequences in downloader metadata, potentially leading to unintended file writes beyond the designated directory. This vulnerability poses significant risks related to unauthorized file access and data exfiltration.
Affected Version(s)
cloudreve 0 < 4.16.1
cloudreve 4.16.1
