go

github.com/cloudreve/Cloudreve/v3

View on go registry
23 Total advisories
23 Vulnerabilities
0 Malware

Dependency scanning

Check whether github.com/cloudreve/Cloudreve/v3 is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 7.1
Go

CVE-2026-54563

Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root

UNKNOWN
Go

CVE-2026-54563

Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root in github.com/cloudreve/Cloudreve

UNKNOWN
Go

GHSA-vx2m-jpxr-xv7w

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/cloudreve/Cloudreve

UNKNOWN
Go

GHSA-w8j7-39hp-8x59

Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve

MEDIUM 5.4
Go

GO-2026-6106

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests

MEDIUM 6.5
Go

CVE-2026-55497

Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server

MEDIUM 4.3
Go

CVE-2026-55499

Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings

MEDIUM 4.3
Go

CVE-2026-55496

Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails

MEDIUM 4.3
Go

CVE-2026-55495

Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account

HIGH 7.1
Go

CVE-2026-55502

Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials

MEDIUM 6.3
Go

CVE-2026-62323

Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored

UNKNOWN
Go

CVE-2026-55495

Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account in github.com/cloudreve/Cloudreve

UNKNOWN
Go

CVE-2026-55502

Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials in github.com/cloudreve/Cloudreve

UNKNOWN
Go

CVE-2026-55499

Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings in github.com/cloudreve/Cloudreve

UNKNOWN
Go

CVE-2026-55496

Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails in github.com/cloudreve/Cloudreve

UNKNOWN
Go

GHSA-v6w6-358x-2433

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve

UNKNOWN
Go

CVE-2026-55497

Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server in github.com/cloudreve/Cloudreve

UNKNOWN
Go

CVE-2026-62323

Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored in github.com/cloudreve/Cloudreve

MEDIUM 6.5
Go

CVE-2026-54562

Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses

UNKNOWN
Go

CVE-2026-54560

Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim in github.com/cloudreve/Cloudreve

UNKNOWN
Go

CVE-2026-54562

Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses in github.com/cloudreve/Cloudreve

UNKNOWN
Go

CVE-2026-25726

Cloudreve is vulnerable to Account Takeover via Weak Cryptographic Token Generation (Insecure PRNG Seeding) in github.com/cloudreve/Cloudreve

MEDIUM 5.4
Go

CVE-2022-32167

Cross site scripting in Cloudreve

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes