—
GO-2026-5350
Cloudreve is vulnerable to Account Takeover via Weak Cryptographic Token Generation (Insecure PRNG Seeding) in github.com/cloudreve/Cloudreve
Details
Cloudreve is vulnerable to Account Takeover via Weak Cryptographic Token Generation (Insecure PRNG Seeding) in github.com/cloudreve/Cloudreve
Are you affected?
Enter the version of the package you're using.
Affected packages
Go / github.com/cloudreve/Cloudreve
Introduced in:
0 No fixed version published yet for github.com/cloudreve/Cloudreve (go modules). Pin to a known-safe version or switch to an alternative.
Go / github.com/cloudreve/Cloudreve/v3
Introduced in:
0 No fixed version published yet for github.com/cloudreve/Cloudreve/v3 (go modules). Pin to a known-safe version or switch to an alternative.
Go / github.com/cloudreve/Cloudreve/v4
Introduced in:
0 Fixed in: 4.0.0-20260205113604-ec9fdd33bc54 Fix
go get github.com/cloudreve/Cloudreve/v4@v4.0.0-20260205113604-ec9fdd33bc54