GO-2026-6098
Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails in github.com/cloudreve/Cloudreve
Quick fix
GO-2026-6098 — github.com/cloudreve/Cloudreve/v4: upgrade to the fixed version with the command below.
go get github.com/cloudreve/Cloudreve/v4@v4.0.0-20260613023921-7e1289d55279Details
Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails in github.com/cloudreve/Cloudreve
Are you affected?
Enter the version of the package you're using.
Affected packages
0No fixed version published yet for github.com/cloudreve/Cloudreve (go modules). Pin to a known-safe version or switch to an alternative.
0No fixed version published yet for github.com/cloudreve/Cloudreve/v3 (go modules). Pin to a known-safe version or switch to an alternative.
0Fixed in: 4.0.0-20260613023921-7e1289d55279go get github.com/cloudreve/Cloudreve/v4@v4.0.0-20260613023921-7e1289d55279