CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-v6w6-358x-2433: Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests

mediumCVSS 5.4
Summary Cloudreve exposes two admin node test endpoints under the Admin.Read OAuth scope. These endpoints accept attacker-controlled node definitions and cause Cloudreve to make outbound server-side network requests. This allows an OAuth client authorized only for Admin.Read to trigger operational network actions that should require Admin.Write. Impact An attacker who obtains an admin-authorized OAuth token with Admin.Read but not Admin.Write can make the Cloudreve server connect to arbitrary URLs supplied in the request body. This can be used for blind SSRF, internal service probing, and triggering signed Cloudreve slave-style requests to attacker-chosen endpoints. Affected version Verified in source and runtime on latest master commit ba2e870bbd17f1918dd2321de861e453f696d6a3 and latest observed tag 4.16.1. Technical details The authenticated admin route group requires only Admin.Read: auth := v4.Group("") auth.Use(middleware.LoginRequired()) auth.Use(middleware.RequiredScopes(types.ScopeAdminRead)) admin := auth.Group("admin", middleware.IsAdmin()) The following routes are registered without ScopeAdminWrite: node.POST("test", controllers.FromJSONadminsvc.TestNodeService, controllers.AdminTestSlave, ) node.POST("test/downloader", controllers.FromJSONadminsvc.TestNodeDownloaderService, controllers.AdminTestDownloader, ) By contrast, node create, update, and delete routes do require Admin.Write: node.PUT("", middleware.RequiredScopes(types.ScopeAdminWrite), ...) node.PUT(":id", middleware.RequiredScopes(types.ScopeAdminWrite), ...) node.DELETE(":id", middleware.RequiredScopes(types.ScopeAdminWrite), ...) TestNodeService.Test() parses the attacker-supplied node server and sends a request to it: slave, err := url.Parse(service.Node.Server) ... res, err := r.Request( "POST", routes.SlavePingRoute(slave), bytes.NewReader(bodyByte), ... ) TestNodeDownloaderService.Test() constructs a downloader from attacker-supplied node settings and invokes its network te

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
medium — CVSS 5.4
Published
2026-07-24
Last updated
2026-07-24
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-v6w6-358x-2433

More from GitHub Security Advisories