HIGH🇵🇱 Wersja polska

CVE-2026-42275

CVSS 8.7v3.1pub. 2026-05-08

zrok is software for sharing web services, files, and network resources. Prior to version 2.0.2, the zrok WebDAV drive backend (davServer.Dir) restricts path traversal through lexical normalization but does not prevent symlink following. When a symbolic link inside the shared DriveRoot points to a location outside that root, remote WebDAV consumers can read files and—on shares without OS-level permission restrictions—write or overwrite files anywhere on the host filesystem accessible to the zrok process. This issue has been patched in version 2.0.2.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
  • Netfoundry Zrok

    APP
    Netfoundry
    < 2.0.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2026-45568CRITICAL9.9PL ✓same product

SSRF via path traversal w zrok Python SDK ProxyShare

CVE-2026-45576HIGH8.3PL ✓same product

Path Traversal w zrok — zapis plików poza docelowym katalogiem

CVE-2026-40303HIGH7.5same product

zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, endpoints.Get...

CVE-2026-40302MEDIUM6.1same product

zrok to oprogramowanie do udostępniania usług internetowych, plików i zasobów sieciowych. Przed wersją 2.0.1 s...

CVE-2026-40304MEDIUM5.3same product

zrok to oprogramowanie służące do udostępniania usług internetowych, plików i zasobów sieciowych. Przed wersją...