HIGH🇵🇱 Wersja polska

CVE-2026-45576

CVSS 8.3v4.0pub. 2026-07-16upd. 2026-07-20

zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `zrok2 copy` stores attacker-controlled WebDAV or zrok drive paths such as /../outside.txt in the source inventory and passes them to FilesystemTarget.WriteStream, allowing the sync pipeline to write files outside the selected local filesystem destination root. This issue is fixed in version 2.0.3.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Netfoundry Zrok

    APP
    Netfoundry
    0.4.23 – 2.0.3 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2026-45568CRITICAL9.9PL ✓same product

SSRF via path traversal w zrok Python SDK ProxyShare

CVE-2026-42275HIGH8.7same product

zrok is software for sharing web services, files, and network resources. Prior to version 2.0.2, the zrok WebD...

CVE-2026-40303HIGH7.5same product

zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, endpoints.Get...

CVE-2026-40302MEDIUM6.1same product

zrok to oprogramowanie do udostępniania usług internetowych, plików i zasobów sieciowych. Przed wersją 2.0.1 s...

CVE-2026-40304MEDIUM5.3same product

zrok to oprogramowanie służące do udostępniania usług internetowych, plików i zasobów sieciowych. Przed wersją...