Server-side Request Forgery Vulnerability in Cloudreve File Management System
CVE-2026-79913

6.5MEDIUM

Key Information:

Vendor

Cloudreve

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-79913?

Cloudreve, a self-hosted file management and sharing platform, contains a server-side request forgery vulnerability due to improper validation of resolved addresses in the ValidateExternalURL function. An authenticated user with remote-download capabilities can exploit this flaw by passing malicious SrcUri inputs through the RemoteDownloadTask.createDownloadTask method. This allows attackers to access private and internal services by misclassifying private, loopback, link-local, or cloud metadata IPv4 addresses as public, leading to potential exposure of sensitive cloud instance credentials and internal service responses. The issue was resolved in version 4.18.0.

Affected Version(s)

cloudreve < 4.18.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.