THREAT OPS › Threat News › [GHSA] GHSA-w8j7-39hp-8x59 (medium) — Cloudreve's remote download file paths can escape the selected destination directory
[GHSA] GHSA-w8j7-39hp-8x59 (medium) — Cloudreve's remote download file paths can escape the selected destination directory
GHSA-w8j7-39hp-8x59 Severity: medium CVE: None
Cloudreve's remote download file paths can escape the selected destination directory
### Summary
Cloudreve trusts file paths returned by the configured remote downloader. A downloader-reported path such as `../../escaped.txt` can cause a downloaded file to be created outside the user-selected destination directory.
### Details
In the remote downl
MITRE ATT&CK techniques
- Malicious FileT1204.002
Indicators of compromise
- http://fake-aria2:6800/jsonrpcurl
- http://attacker.invalid/fileurl
Original source: https://github.com/advisories/GHSA-w8j7-39hp-8x59