GO-2026-6298
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root in github.com/cloudreve/Cloudreve
Quick fix
GO-2026-6298 — github.com/cloudreve/Cloudreve/v4: upgrade to the fixed version with the command below.
go get github.com/cloudreve/Cloudreve/v4@v4.0.0-20260606032813-26b6b1044b02 Details
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root in github.com/cloudreve/Cloudreve
Are you affected?
Enter the version of the package you're using.
Affected packages
0 No fixed version published yet for github.com/cloudreve/Cloudreve (go modules). Pin to a known-safe version or switch to an alternative.
0 No fixed version published yet for github.com/cloudreve/Cloudreve/v3 (go modules). Pin to a known-safe version or switch to an alternative.
0 Fixed in: 4.0.0-20260606032813-26b6b1044b02 go get github.com/cloudreve/Cloudreve/v4@v4.0.0-20260606032813-26b6b1044b02