CVE Explorer
CVE-2026-44184
Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, Cleanuparr's global CORS policy reflects every request Origin and combines it with AllowCredentials(). When DisableAuthForLocalAddresses is enabled, the API also authenticates requests purely by source IP via TrustedNetworkAuthenticationHandler. The combination lets any website that an admin (or any user on a trusted IP) visits read au
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-942","description":"CWE-942: Permissive Cross-domain Policy with Untrusted Domains","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:3afd5d9e7bbdffbf75654a7cb1465e5700dd660781389931d85e2bb5f833f2d7 · sha256:61c8228c449eb22b… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-346","description":"CWE-346: Origin Validation Error","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:3afd5d9e7bbdffbf75654a7cb1465e5700dd660781389931d85e2bb5f833f2d7 · sha256:61c8228c449eb22b… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"Cleanuparr","vendor":"Cleanuparr","versions":[{"status":"affected","version":"< 2.9.10"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:3afd5d9e7bbdffbf75654a7cb1465e5700dd660781389931d85e2bb5f833f2d7 · sha256:61c8228c449eb22b… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"HIGH","baseScore":8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:3afd5d9e7bbdffbf75654a7cb1465e5700dd660781389931d85e2bb5f833f2d7 · sha256:61c8228c449eb22b… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-942","description":"CWE-942: Permissive Cross-domain Policy with Untrusted Domains","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:3afd5d9e7bbdffbf75654a7cb1465e5700dd660781389931d85e2bb5f833f2d7 · sha256:61c8228c449eb22b… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-346","description":"CWE-346: Origin Validation Error","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:3afd5d9e7bbdffbf75654a7cb1465e5700dd660781389931d85e2bb5f833f2d7 · sha256:61c8228c449eb22b… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["exploit"],"url":"https://github.com/Cleanuparr/Cleanuparr/security/advisories/GHSA-rwpc-36mg-fpvf"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3afd5d9e7bbdffbf75654a7cb1465e5700dd660781389931d85e2bb5f833f2d7 · sha256:61c8228c449eb22b… · /containers/adp/0/references/0
{"name":"https://github.com/Cleanuparr/Cleanuparr/security/advisories/GHSA-rwpc-36mg-fpvf","tags":["x_refsource_CONFIRM"],"url":"https://github.com/Cleanuparr/Cleanuparr/security/advisories/GHSA-rwpc-36mg-fpvf"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3afd5d9e7bbdffbf75654a7cb1465e5700dd660781389931d85e2bb5f833f2d7 · sha256:61c8228c449eb22b… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.