Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/cloudreve/Cloudreve/v4
  4. ›
  5. CVE-2026-54562

CVE-2026-54562: Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses

July 20, 2026

Cloudreve’s remote download workflow accepts user-supplied URLs and passes them to the configured downloader without blocking loopback, localhost, IPv6 localhost, or redirect-to-loopback targets.

When the remote download permission is granted to a non-admin user group, a normal authenticated user can make the server-side downloader fetch internal-only URLs and then read the fetched response after it is imported into the user’s own Cloudreve files.

This does not affect default normal users unless the remote download permission is enabled for their group. However, the permission is a feature-level user-group capability and does not make the user an administrator.

References

  • github.com/advisories/GHSA-x756-g4x3-c64m
  • github.com/cloudreve/cloudreve/commit/aaebf317a78f2413d74afd66c21a1f3143711312
  • github.com/cloudreve/cloudreve/releases/tag/4.16.1
  • github.com/cloudreve/cloudreve/security/advisories/GHSA-x756-g4x3-c64m
  • nvd.nist.gov/vuln/detail/CVE-2026-54562

Code Behaviors & Features

Detect and mitigate CVE-2026-54562 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 4.0.0-20260606025411-aaebf317a78f

Fixed versions

  • 4.0.0-20260606025411-aaebf317a78f

Solution

Upgrade to version 4.0.0-20260606025411-aaebf317a78f or above.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-918: Server-Side Request Forgery (SSRF)

Source file

go/github.com/cloudreve/Cloudreve/v4/CVE-2026-54562.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Aug 2026 00:18:35 +0000.