CVE-2026-101051 - Cloudreve before 4.16.1 Path Traversal via Remote Download
CVE ID :CVE-2026-101051
Published : Sept. 27, 2026, 6:16 p.m. | 55 minutes ago
Description :Cloudreve before 4.16.1 fails to properly sanitize file paths returned by remote downloaders, allowing authenticated users to create files outside the selected destination directory. Attackers can exploit path traversal sequences in downloader metadata to write files to unexpected locations within accessible namespaces.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 27, 2026, 6:16 p.m. | 55 minutes ago
Description :Cloudreve before 4.16.1 fails to properly sanitize file paths returned by remote downloaders, allowing authenticated users to create files outside the selected destination directory. Attackers can exploit path traversal sequences in downloader metadata to write files to unexpected locations within accessible namespaces.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...