Server-side Request Forgery Vulnerability in Cloudreve File Management System
CVE-2026-79913
6.5MEDIUM
What is CVE-2026-79913?
Cloudreve, a self-hosted file management and sharing platform, contains a server-side request forgery vulnerability due to improper validation of resolved addresses in the ValidateExternalURL function. An authenticated user with remote-download capabilities can exploit this flaw by passing malicious SrcUri inputs through the RemoteDownloadTask.createDownloadTask method. This allows attackers to access private and internal services by misclassifying private, loopback, link-local, or cloud metadata IPv4 addresses as public, leading to potential exposure of sensitive cloud instance credentials and internal service responses. The issue was resolved in version 4.18.0.
Affected Version(s)
cloudreve < 4.18.0
