CVE-2026-45576
HIGHzrok copy writes attacker-controlled WebDAV paths outside the destination root
Title source: cnaDescription
zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `zrok2 copy` stores attacker-controlled WebDAV or zrok drive paths such as /../outside.txt in the source inventory and passes them to FilesystemTarget.WriteStream, allowing the sync pipeline to write files outside the selected local filesystem destination root. This issue is fixed in version 2.0.3.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/openziti/zrok/security/advisories/GHSA-c656-jcx2-7pqj
X_Refsource_Misc x_refsource_misc
https://github.com/openziti/zrok/commit/a5811e61589d2f804267c6de4a9056db1bdea457
X_Refsource_Misc x_refsource_misc
https://github.com/openziti/zrok/releases/tag/v2.0.3
Scores
CVSS v3
7.5
EPSS
0.0034
EPSS Percentile
26.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (2)
netfoundry/zrok
0.4.23 - 2.0.3
openziti/zrok
>= 0.4.23, < 2.0.3
Published
Jul 16, 2026
Tracked Since
Jul 16, 2026