CyberRota Analysis
AI-GeneratedThe vulnerability in zrok allows attackers to manipulate the `zrok2 copy` command to store malicious WebDAV or zrok drive paths, enabling unauthorized file writes outside the intended local filesystem destination. This could lead to data exposure or corruption, making it critical for organizations using versions 0.4.23 to 2.0.2 to prioritize upgrading to version 2.0.3 to mitigate potential risks. Users of this software should act promptly to secure their systems against this high-severity issue.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `zrok2 copy` stores attacker-controlled WebDAV or zrok drive paths such as /../outside.txt in the source inventory and passes them to FilesystemTarget.WriteStream, allowing the sync pipeline to write files outside the selected local filesystem destination root. This issue is fixed in version 2.0.3.
Related CVEs
Other vulnerabilities affecting the same vendor(s)