Commit Graph
1 Commits
Author SHA1 Message Date
Cursor Agentandqaiu efbadde4ed fix(security): harden GHSA-997r Cloudreve SSRF residual paths
Disable redirect following on CE/Ce4 attacker-controlled requests and stop
echoing upstream response bodies in client-facing JSON errors. Add
assertPublicHost regression coverage for the advisory PoC hosts.

Co-authored-by: qaiu <[email protected]>
2026-07-26 12:05:16 +00:00