VDB

GO-2026-6298

Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root in github.com/cloudreve/Cloudreve

Quick fix

GO-2026-6298 — github.com/cloudreve/Cloudreve/v4: upgrade to the fixed version with the command below.

go get github.com/cloudreve/Cloudreve/v4@v4.0.0-20260606032813-26b6b1044b02

Details

Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root in github.com/cloudreve/Cloudreve

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / github.com/cloudreve/Cloudreve
Introduced in: 0

No fixed version published yet for github.com/cloudreve/Cloudreve (go modules). Pin to a known-safe version or switch to an alternative.

Go / github.com/cloudreve/Cloudreve/v3
Introduced in: 0

No fixed version published yet for github.com/cloudreve/Cloudreve/v3 (go modules). Pin to a known-safe version or switch to an alternative.

Go / github.com/cloudreve/Cloudreve/v4
Introduced in: 0 Fixed in: 4.0.0-20260606032813-26b6b1044b02
Fix go get github.com/cloudreve/Cloudreve/v4@v4.0.0-20260606032813-26b6b1044b02

References