V4: Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
Cloudreve v4 exposes two admin node test endpoints that require only the Admin.Read OAuth scope but allow triggering server-side network requests to attacker-controlled URLs. This enables an attacker with an Admin.Read-only OAuth token to perform blind SSRF and internal service probing, actions that should require Admin.Write scope. The issue was verified in version 4.16.1 and the latest master commit. The root cause is missing Admin.Write scope enforcement on these test endpoints, which perform outbound network requests using attacker-supplied configuration.
AI Analysis
Technical Summary
Cloudreve v4 has a vulnerability where two admin node test endpoints under the Admin.Read OAuth scope accept attacker-controlled node definitions and cause the server to make outbound network requests. Although node create, update, and delete routes require Admin.Write scope, these test endpoints do not, allowing an attacker with only Admin.Read scope to trigger server-side requests to arbitrary URLs. This was confirmed on version 4.16.1 and the latest master commit. The issue arises because the route group enforces Admin.Read by default and relies on per-route Admin.Write middleware for state-mutating operations, but the test endpoints were omitted from this stricter scope requirement. The vulnerability enables blind SSRF, internal service probing, and triggering signed requests to attacker-chosen endpoints.
Potential Impact
An attacker who obtains an OAuth token with only Admin.Read scope can cause the Cloudreve server to connect to arbitrary URLs specified in the request body via the node test endpoints. This allows blind server-side request forgery (SSRF), internal network reconnaissance, and potentially triggering signed Cloudreve slave-style requests to endpoints controlled by the attacker. The attacker cannot perform node create, update, or delete operations without Admin.Write scope, but can still cause operational network actions that should be restricted.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The recommended remediation is to add Admin.Write scope enforcement middleware to the node test endpoints to prevent Admin.Read-only tokens from triggering server-side network requests. Additionally, applying SSRF validation or network egress controls on all admin-supplied test URLs is advised. Auditing other admin test endpoints for similar read-scoped side effects is also recommended.
V4: Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
Description
Cloudreve v4 exposes two admin node test endpoints that require only the Admin.Read OAuth scope but allow triggering server-side network requests to attacker-controlled URLs. This enables an attacker with an Admin.Read-only OAuth token to perform blind SSRF and internal service probing, actions that should require Admin.Write scope. The issue was verified in version 4.16.1 and the latest master commit. The root cause is missing Admin.Write scope enforcement on these test endpoints, which perform outbound network requests using attacker-supplied configuration.
CVSS v3.1
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Cloudreve v4 has a vulnerability where two admin node test endpoints under the Admin.Read OAuth scope accept attacker-controlled node definitions and cause the server to make outbound network requests. Although node create, update, and delete routes require Admin.Write scope, these test endpoints do not, allowing an attacker with only Admin.Read scope to trigger server-side requests to arbitrary URLs. This was confirmed on version 4.16.1 and the latest master commit. The issue arises because the route group enforces Admin.Read by default and relies on per-route Admin.Write middleware for state-mutating operations, but the test endpoints were omitted from this stricter scope requirement. The vulnerability enables blind SSRF, internal service probing, and triggering signed requests to attacker-chosen endpoints.
Potential Impact
An attacker who obtains an OAuth token with only Admin.Read scope can cause the Cloudreve server to connect to arbitrary URLs specified in the request body via the node test endpoints. This allows blind server-side request forgery (SSRF), internal network reconnaissance, and potentially triggering signed Cloudreve slave-style requests to endpoints controlled by the attacker. The attacker cannot perform node create, update, or delete operations without Admin.Write scope, but can still cause operational network actions that should be restricted.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The recommended remediation is to add Admin.Write scope enforcement middleware to the node test endpoints to prevent Admin.Read-only tokens from triggering server-side network requests. Additionally, applying SSRF validation or network egress controls on all admin-supplied test URLs is advised. Auditing other admin test endpoints for similar read-scoped side effects is also recommended.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-v6w6-358x-2433
- Osv Schema Version
- 1.4.0
- Aliases
- []
- Ecosystems
- ["Go"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a6542219c2644c7f80884b3
Added to database: 07/25/2026, 23:09:21 UTC
Last enriched: 07/25/2026, 23:51:45 UTC
Last updated: 07/26/2026, 03:59:00 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.