Sceawere

Vulnerability Detail

CVE-2026-101051UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Cloudreve Path Traversal Vulnerability

Vulnerability Metadata

Severity
Low
Score / CVSS
3.1
Creation Date
14h ago
Vendor
cloudreve
Product
cloudreve
Attack Type
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Cloudreve before 4.16.1 fails to properly sanitize file paths returned by remote downloaders, allowing authenticated users to create files outside the selected destination directory. Attackers can exploit path traversal sequences in downloader metadata to write files to unexpected locations within accessible namespaces.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.1",
  "pubDate": "2026-09-27T18:16:31.510Z",
  "pubdate": "2026-09-27T18:16:31.510Z",
  "executiveSummary": "Cloudreve versions prior to 4.16.1 contain a path traversal vulnerability resulting from insufficient input sanitization during remote file download operations.\nThe vulnerability resides in the downloader component, where metadata provided by external sources is not properly validated against the defined application storage directory.\nAn authenticated attacker can leverage malicious path traversal sequences embedded within the remote downloader metadata to force the application to write files to arbitrary locations within the server's accessible file system.\nThis flaw allows for unauthorized file creation, which could potentially be leveraged for further system compromise depending on the target location and the application's environment.\nExploitation requires the attacker to possess authenticated access to the application, specifically the ability to initiate remote download requests.\nThe risk is significant as it breaks the intended directory containment, providing an attacker with write access outside the designated storage namespaces.",
  "technicalDetails": "The vulnerability is a classic path traversal flaw originating from the improper processing of user-supplied or metadata-derived file paths within the Cloudreve remote downloader component.\nWhen a user triggers a remote download, the application parses metadata associated with the remote file to determine the local destination. The root cause is the failure of the application to sanitize or normalize these paths before file system operations are performed.\nSpecifically, the application logic fails to implement effective jail or chroot-like restrictions to ensure that file writes remain confined to the designated storage directory. Because the system directly incorporates pathing information from the downloader metadata, an attacker can supply sequences such as '../' to escape the intended directory tree.\nThe attack flow proceeds as follows: First, the attacker initiates a remote download operation through the Cloudreve interface. Second, the attacker intercept or constructs a request that includes manipulated metadata containing traversal sequences (e.g., ../../../target_path/malicious_file). Third, the Cloudreve downloader processes the request, fails to identify or neutralize the traversal sequences, and subsequently utilizes the resulting path string in a file creation or move operation.\nThe application performs these operations with the privileges of the system user running the Cloudreve service, meaning the vulnerability allows the writing of files to any location accessible to that service account.\nThis behavior affects Cloudreve versions prior to 4.16.1. Successful exploitation requires an authenticated session, but it does not require additional administrative privileges, significantly lowering the barrier for entry for any registered user.\nThe impact of successful exploitation is substantial. By controlling the location where a file is saved, an attacker might overwrite critical configuration files, drop malicious scripts into executable paths (if reachable), or perform unauthorized data modification within the file system namespaces that the application process can influence.\nThe vulnerability persists until the application logic explicitly validates that the resolved absolute path of the destination remains a strict sub-directory of the intended storage root, effectively neutralizing traversal characters before any file write operation occurs."
}
CVE-2026-101051: Cloudreve Path Traversal Vulnerability (LOW Severity, CVSS: 3.1) | Sceawere