๐Ÿ” CVE Alert

CVE-2026-44184

HIGH 8.0

Cleanuparr: Reflective CORS combined with trusted-network auth allows cross-origin admin API reads

CVSS Score
8.0
EPSS Score
0.0%
EPSS Percentile
0th

Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, Cleanuparr's global CORS policy reflects every request Origin and combines it with AllowCredentials(). When DisableAuthForLocalAddresses is enabled, the API also authenticates requests purely by source IP via TrustedNetworkAuthenticationHandler. The combination lets any website that an admin (or any user on a trusted IP) visits read authenticated API responses cross-origin โ€” including the admin's permanent API key. This vulnerability is fixed in 2.9.10.

CWE CWE-346 CWE-942
Vendor cleanuparr
Product cleanuparr
Published May 12, 2026
Last Updated May 12, 2026
Stay Ahead of the Next One

Get instant alerts for cleanuparr cleanuparr

Be the first to know when new high vulnerabilities affecting cleanuparr cleanuparr are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Cleanuparr / Cleanuparr
< 2.9.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Cleanuparr/Cleanuparr/security/advisories/GHSA-rwpc-36mg-fpvf