CRITICAL🇵🇱 Wersja polska

CVE-2026-45568

CVSS 9.9v4.0pub. 2026-07-16upd. 2026-07-20

zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the request path and passes it to urllib.parse.urljoin, allowing the requested path to replace the configured target host and causing requests.request to return a server-side response from an attacker-chosen URL. This issue is fixed in version 2.0.3.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Netfoundry Zrok

    APP
    Netfoundry
    0.4.47 – 2.0.3 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2026-45576HIGH8.3PL ✓same product

Path Traversal w zrok — zapis plików poza docelowym katalogiem

CVE-2026-42275HIGH8.7same product

zrok is software for sharing web services, files, and network resources. Prior to version 2.0.2, the zrok WebD...

CVE-2026-40303HIGH7.5same product

zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, endpoints.Get...

CVE-2026-40302MEDIUM6.1same product

zrok to oprogramowanie do udostępniania usług internetowych, plików i zasobów sieciowych. Przed wersją 2.0.1 s...

CVE-2026-40304MEDIUM5.3same product

zrok to oprogramowanie służące do udostępniania usług internetowych, plików i zasobów sieciowych. Przed wersją...