PT-2026-37189 · Zrok · Zrok
Published
2026-04-25
·
Updated
2026-05-09
·
CVE-2026-42275
CVSS v3.1
8.7
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
zrok versions prior to 2.0.2
Description
The zrok WebDAV drive backend
davServer.Dir restricts path traversal through lexical normalization but fails to prevent symlink following. If a symbolic link within the shared DriveRoot points to a location outside that root, remote WebDAV consumers can read files. On shares lacking OS-level permission restrictions, attackers can also write to or overwrite files anywhere on the host filesystem accessible to the zrok process. This occurs because the WebDAV PUT handler opens files with O RDWR|O CREATE|O TRUNC. The issue affects the Dir.OpenFile(), Dir.Stat(), Dir.Mkdir(), and Dir.RemoveAll() functions in drives/davServer/file.go, as well as NewBackend() in endpoints/drive/backend.go.Recommendations
Update to version 2.0.2.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zrok