mediumCVSS 5.4Vulnerability

GHSA-v6w6-358x-2433

## Summary Cloudreve exposes two admin node test endpoints under the `Admin.Read` OAuth scope. These endpoints accept attacker-controlled node definitions and cause Cloudreve to make outbound server-side network requests. This allows an OAuth client authorized only for `Admin.Read` to trigger operational network actions that should require `Admin.Write`. ## Impact An attacker who obtains an admin-authorized OAuth token with `Admin.Read` but not `Admin.Write` can make the Cloudreve server connect to arbitrary URLs supplied in the request body. This can be used for blind SSRF, internal service probing, and triggering signed Cloudreve slave-style requests to attacker-chosen endpoints. ## Affected version Verified in source and runtime on latest master commit `ba2e870bbd17f1918dd2321de861e453f696d6a3` and latest observed tag `4.16.1`. ## Technical details The authenticated admin route group requires only `Admin.Read`: ```go auth := v4.Group("") auth.Use(middleware.LoginRequired()) auth.Use(middleware.RequiredScopes(types.ScopeAdminRead)) admin := auth.Group("admin", middleware.IsAdmin()) ``` The following routes are registered without `ScopeAdminWrite`: ```go node.POST("test", controllers.FromJSON[adminsvc.TestNodeService](adminsvc.TestNodeParamCtx{}), controllers.AdminTestSlave, ) node.POST("test/downloader", controllers.FromJSON[adminsvc.TestNodeDownloaderService](adminsvc.TestNodeDownloaderParamCtx{}), controllers.AdminTestDownloader, ) ``` By contrast, node create, update, and delete routes do require `Admin.Write`: ```go node.PUT("", middleware.RequiredScopes(types.ScopeAdminWrite), ...) node.PUT(":id", middleware.RequiredScopes(types.ScopeAdminWrite), ...) node.DELETE(":id", middleware.RequiredScopes(types.ScopeAdminWrite), ...) ``` `TestNodeService.Test()` parses the attacker-supplied node server and sends a request to it: ```go slave, err := url.Parse(service.Node.Server) ... res, err := r.Request( "POST", routes.SlavePingRo

Properties

ghsa_id
GHSA-v6w6-358x-2433
severity
medium
summary
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
cvss_score
5.4
cve_id
GHSA-v6w6-358x-2433
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
is_ghsa_only
true
ghsa_published
2026-07-24T21:50:23Z
source_url
https://github.com/advisories/GHSA-v6w6-358x-2433
ghsa_updated
2026-07-24T21:50:25Z

Related Entities (7)

AFFECTS (2)

[Software]go/github.com/cloudreve/Cloudreve/v4
[Software]go/github.com/cloudreve/Cloudreve/v3

HAS_WEAKNESS (2)

[Weakness]Incorrect Authorization
[Weakness]Server-Side Request Forgery (SSRF)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (2)

[Software]go/github.com/cloudreve/Cloudreve/v4
[Software]go/github.com/cloudreve/Cloudreve/v3

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-v6w6-358x-2433 (CVSS 5.4) — Ninja Signal Threat Intelligence | Ninja Signal