CVE-2026-54562

MEDIUM

Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses

Title source: cna
STIX 2.1

Description

Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, Cloudreve's remote download workflow accepts user-supplied URLs at POST /api/v4/workflow/download and passes them to the configured downloader without blocking loopback, localhost, IPv6 localhost, or redirect-to-loopback targets, allowing a non-admin user with remote download permission to fetch internal-only URLs and read the response after it is imported into the user's own files. This issue is fixed in version 4.16.1.

Scores

CVSS v3 6.5
EPSS 0.0024
EPSS Percentile 15.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (3)
cloudreve/Cloudreve 0 - 3.0.0-20250225100611-da4e44b77af4Go
cloudreve/Cloudreve 0 - 4.0.0-20260606025411-aaebf317a78fGo
cloudreve/cloudreve < 4.16.1
Published Jul 15, 2026
Tracked Since Jul 15, 2026