File Management Vulnerability in Cloudreve File Sharing System
CVE-2026-55495
4.3MEDIUM
What is CVE-2026-55495?
Cloudreve, a self-hosted file management and sharing system, is susceptible to a path traversal vulnerability in its WOPI PUT_RELATIVE handler. This flaw occurs prior to version 4.17.0, where the handler erroneously processes the X-WOPI-SuggestedTarget as a path rather than as a filename. This oversight enables attackers to manipulate file paths, potentially allowing them to escape the designated file directory and create or overwrite files in unauthorized locations within the same user account. The issue has been addressed in version 4.17.0.
Affected Version(s)
cloudreve < 4.17.0
