<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 20:00:00 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-343470</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-343470</link>
      <description>EUVD-2026-343470</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-343470</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55495</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55495</link>
      <description>&lt;p&gt;Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-WOPI-SuggestedTarget to URI.JoinRaw as a path rather than a filename, allowing slash and dot-dot segments to escape the source file directory and create or conditionally overwrite files elsewhere in the same owner account. This issue is fixed in version 4.17.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-WOPI-SuggestedTarget to URI.JoinRaw as a path rather than a filename, allowing slash and dot-dot segments to escape the source file directory and create or conditionally overwrite files elsewhere in the same owner account. This issue is fixed in version 4.17.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55495</guid>
    </item>
    <item>
      <title>GHSA-49h3-cwhj-4737 — Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-49h3-cwhj-4737</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/cloudreve/Cloudreve/v4, Go: github.com/cloudreve/Cloudreve/v3&lt;/p&gt;
&lt;p&gt;## Summary
 
Cloudreve&amp;#39;s WOPI `PUT_RELATIVE` handler treats `X-WOPI-SuggestedTarget` as a path, not a filename. It splits the header on `/` and joins the segments onto the source file&amp;#39;s directory with `URI.JoinRaw`, which feeds Go&amp;#39;s `url.JoinPath`. `url.JoinPath` resolves `.`/`..` segments, so a slash-bearing target such as `a/../../evil.docx` collapses to a location outside the source file&amp;#39;s directory. The lower-level upload path then validates only the final, already-cleaned basename (`evil.docx`), which is harmless, and checks ownership against the *resolved ancestor* — which is still the same user&amp;#39;s drive.
 
A WOPI access token is bound to exactly one file (the route enforces `fileId == session.FileID` with a 403 otherwise). `PUT_RELATIVE` escapes that per-file scope: a token issued for one file can create (and, conditionally, overwrite) files elsewhere in the same account.&lt;/p&gt;
&lt;p&gt;## Root cause (verified at `26b6b10`)
 
**1. Token is single-file scoped (the boundary being escaped)** — `middleware` `ViewerSessionValidation`:
 
```go
fileId := hashid.FromContext(c)
if fileId != session.FileID {           // 403 — token is bound to ONE file
    c.Status(http.StatusForbidden); c.Abort(); return
}
```
 
Route: `wopi := noAuth.Group(&amp;#34;file/wopi&amp;#34;, middleware.HashID(hashid.FileID), middleware.ViewerSessionValidation())`; `wopi.POST(&amp;#34;:id&amp;#34;, controllers.ModifyFile)` → `POST /api/v4/file/wopi/:id?access_token=&amp;lt;token&amp;gt;`.
 
**2. `PUT_RELATIVE` dispatch** — `routers/controllers/wopi.go`:
 
```…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/cloudreve/Cloudreve/v4, Go: github.com/cloudreve/Cloudreve/v3&lt;/p&gt;
&lt;p&gt;## Summary
 
Cloudreve&amp;#39;s WOPI `PUT_RELATIVE` handler treats `X-WOPI-SuggestedTarget` as a path, not a filename. It splits the header on `/` and joins the segments onto the source file&amp;#39;s directory with `URI.JoinRaw`, which feeds Go&amp;#39;s `url.JoinPath`. `url.JoinPath` resolves `.`/`..` segments, so a slash-bearing target such as `a/../../evil.docx` collapses to a location outside the source file&amp;#39;s directory. The lower-level upload path then validates only the final, already-cleaned basename (`evil.docx`), which is harmless, and checks ownership against the *resolved ancestor* — which is still the same user&amp;#39;s drive.
 
A WOPI access token is bound to exactly one file (the route enforces `fileId == session.FileID` with a 403 otherwise). `PUT_RELATIVE` escapes that per-file scope: a token issued for one file can create (and, conditionally, overwrite) files elsewhere in the same account.&lt;/p&gt;
&lt;p&gt;## Root cause (verified at `26b6b10`)
 
**1. Token is single-file scoped (the boundary being escaped)** — `middleware` `ViewerSessionValidation`:
 
```go
fileId := hashid.FromContext(c)
if fileId != session.FileID {           // 403 — token is bound to ONE file
    c.Status(http.StatusForbidden); c.Abort(); return
}
```
 
Route: `wopi := noAuth.Group(&amp;#34;file/wopi&amp;#34;, middleware.HashID(hashid.FileID), middleware.ViewerSessionValidation())`; `wopi.POST(&amp;#34;:id&amp;#34;, controllers.ModifyFile)` → `POST /api/v4/file/wopi/:id?access_token=&amp;lt;token&amp;gt;`.
 
**2. `PUT_RELATIVE` dispatch** — `routers/controllers/wopi.go`:
 
```…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-49h3-cwhj-4737</guid>
    </item>
  </channel>
</rss>
