CVE 8 HIGH

Cleanuparr: Reflective CORS combined with trusted-network auth allows cross-origin admin API reads_CVE-2026-44184

8 / 10
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, Cleanuparr's global CORS policy reflects every request Origin and combines it with AllowCredentials(). When DisableAuthForLocalAddresses is enabled, the API also authenticates requests purely by source IP via TrustedNetworkAuthenticationHandler. The combination lets any website that an admin (or any user on a trusted IP) visits read authenticated API responses cross-origin — including the admin's permanent API key. This vulnerability is fixed in 2.9.10.

Basic Information

ID CVE-2026-44184
Source GitHub_M
Published May 12, 2026 at 17:33

Affected Product

Vendor Cleanuparr
Product Cleanuparr
Version < 2.9.10
Affected Versions Cleanuparr Cleanuparr < 2.9.10

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.