PT-2026-41960 · Zrok · Zrok
CVE-2026-45576
·
Published
2026-05-19
·
Updated
2026-07-30
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
zrok (affected versions not specified)
Description
A path traversal issue exists when using the
zrok2 copy command to move files from a WebDAV or zrok drive to a local filesystem. An attacker can provide a malicious DAV href containing directory traversal sequences, such as /../outside.txt. This path is processed by the FilesystemTarget.WriteStream function, which joins the input with the target root, allowing files to be created or overwritten outside the intended destination directory using the credentials of the user performing the sync.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zrok