<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T09:38:14.345020+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-343470</id>
    <title>EUVD-2026-343470</title>
    <updated>2026-10-06T09:38:14.390641+00:00</updated>
    <content>EUVD-2026-343470</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-343470"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55495</id>
    <title>fkie_cve-2026-55495</title>
    <updated>2026-10-06T09:38:14.390678+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-WOPI-SuggestedTarget to URI.JoinRaw as a path rather than a filename, allowing slash and dot-dot segments to escape the source file directory and create or conditionally overwrite files elsewhere in the same owner account. This issue is fixed in version 4.17.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-55495"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-49h3-cwhj-4737</id>
    <title>GHSA-49h3-cwhj-4737 — Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account</title>
    <updated>2026-10-06T09:38:14.390711+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/cloudreve/Cloudreve/v4, Go: github.com/cloudreve/Cloudreve/v3</p>
<p>## Summary
 
Cloudreve's WOPI `PUT_RELATIVE` handler treats `X-WOPI-SuggestedTarget` as a path, not a filename. It splits the header on `/` and joins the segments onto the source file's directory with `URI.JoinRaw`, which feeds Go's `url.JoinPath`. `url.JoinPath` resolves `.`/`..` segments, so a slash-bearing target such as `a/../../evil.docx` collapses to a location outside the source file's directory. The lower-level upload path then validates only the final, already-cleaned basename (`evil.docx`), which is harmless, and checks ownership against the *resolved ancestor* — which is still the same user's drive.
 
A WOPI access token is bound to exactly one file (the route enforces `fileId == session.FileID` with a 403 otherwise). `PUT_RELATIVE` escapes that per-file scope: a token issued for one file can create (and, conditionally, overwrite) files elsewhere in the same account.</p>
<p>## Root cause (verified at `26b6b10`)
 
**1. Token is single-file scoped (the boundary being escaped)** — `middleware` `ViewerSessionValidation`:
 
```go
fileId := hashid.FromContext(c)
if fileId != session.FileID {           // 403 — token is bound to ONE file
    c.Status(http.StatusForbidden); c.Abort(); return
}
```
 
Route: `wopi := noAuth.Group("file/wopi", middleware.HashID(hashid.FileID), middleware.ViewerSessionValidation())`; `wopi.POST(":id", controllers.ModifyFile)` → `POST /api/v4/file/wopi/:id?access_token=&lt;token&gt;`.
 
**2. `PUT_RELATIVE` dispatch** — `routers/controllers/wopi.go`:
 
```…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-49h3-cwhj-4737"/>
  </entry>
</feed>
