Skip to content

Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails

Moderate severity GitHub Reviewed Published Jul 23, 2026 in cloudreve/cloudreve • Updated Jul 24, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts