This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+1 more
ReleasePort's take
Moderate signalCloudreve 4.18.0 patches multiple security vulnerabilities affecting Community Edition thumbnails, uploads, and share links.
Why it matters: Fixes high‑severity (severity 95) security issues in Community Edition; operators should upgrade immediately to protect thumbnail generation and upload flows.
Summary
AI summaryMultiple security vulnerabilities were fixed in Cloudreve Community Edition.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes multiple security vulnerabilities in Community Edition. Fixes multiple security vulnerabilities in Community Edition. Source: llm_adapter@2026-07-15 Confidence: low |
— |
| Security | High |
Addresses multiple security vulnerabilities. Addresses multiple security vulnerabilities. Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Feature | Low |
Adds one-click empty recycle bin functionality. Adds one-click empty recycle bin functionality. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Adds Pro feature to pin shared folders/files to user sidebar via group settings. Adds Pro feature to pin shared folders/files to user sidebar via group settings. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Optionally allows `__` as separator when overriding config items with environment variables. Optionally allows `__` as separator when overriding config items with environment variables. Source: llm_adapter@2026-07-15 Confidence: low |
— |
| Feature | Low |
Optionally uses `__` as separator for configuration overrides with environment variables. Optionally uses `__` as separator for configuration overrides with environment variables. Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Bugfix | Medium |
Improves CAPTCHA handling by automatically clearing input after incorrect entry. Improves CAPTCHA handling by automatically clearing input after incorrect entry. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Fixes thumbnail generation failure for Community Edition share links. Fixes thumbnail generation failure for Community Edition share links. Source: llm_adapter@2026-07-15 Confidence: low |
— |
| Bugfix | Medium |
Fixes upload failures on local storage policy after enabling parallel chunked uploads. Fixes upload failures on local storage policy after enabling parallel chunked uploads. Source: llm_adapter@2026-07-15 Confidence: low |
— |
Full changelog
- New: One-click empty recycle bin (#3473)
- Details
- New: [Pro] Pin shared folders or files to a user's sidebar via group settings
- Details
- New: Optionally use
__as the separator when overriding configuration items with environment variables (#3498) - Improved: Automatically clear the input after an incorrect CAPTCHA entry (cloudreve/frontend#343 @jcbl1)
- Fixed: [Community Edition] Thumbnails could not be generated when accessed via share links (#3495)
- Fixed: Uploads failed on the local storage policy after enabling parallel chunked uploads
- Fixed: Multiple security vulnerabilities. Full details will be disclosed after 30 days. Thanks to @newugly, @de3erve-hunter, and @tonghuaroot for reporting.
Security Fixes
- Multiple security vulnerabilities were fixed (details disclosed after 30 days)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About cloudreve
Self-hosted file management and sharing system, supports multiple storage providers
Related context
Related tools
Beta — feedback welcome: [email protected]