THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-w8j7-39hp-8x59 (medium) — Cloudreve's remote download file paths can escape the selected destination directory

[GHSA] GHSA-w8j7-39hp-8x59 (medium) — Cloudreve's remote download file paths can escape the selected destination directory

highgithub_advisoriesPublished 2026-08-24

GHSA-w8j7-39hp-8x59 Severity: medium CVE: None

Cloudreve's remote download file paths can escape the selected destination directory

### Summary

Cloudreve trusts file paths returned by the configured remote downloader. A downloader-reported path such as `../../escaped.txt` can cause a downloaded file to be created outside the user-selected destination directory.

### Details

In the remote downl

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-w8j7-39hp-8x59