PT-2026-41960 · Zrok · Zrok

CVE-2026-45576

·

Published

2026-05-19

·

Updated

2026-07-30

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions zrok (affected versions not specified)
Description A path traversal issue exists when using the zrok2 copy command to move files from a WebDAV or zrok drive to a local filesystem. An attacker can provide a malicious DAV href containing directory traversal sequences, such as /../outside.txt. This path is processed by the FilesystemTarget.WriteStream function, which joins the input with the target root, allowing files to be created or overwritten outside the intended destination directory using the credentials of the user performing the sync.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45576
GHSA-C656-JCX2-7PQJ
GO-2026-5315
OPENSUSE-SU-2026:21483-1

Affected Products

Zrok