A high-severity vulnerability was discovered in zrok software, affecting versions from 0.4.23 to 2.0.3. The issue allows attackers to write files outside the selected local filesystem destination root via path traversal. This vulnerability exists in the `zrok2 copy` command, which stores attacker-controlled WebDAV or zrok drive paths and passes them to FilesystemTarget.WriteStream. This allows the sync pi [truncated]
The CVE record for CVE-2026-45568 was published on 2026-07-16T17:16:56.423Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This critical vulnerability affects zrok's Python SDK ProxyShare Flask proxy route, allowing an attacker to replace the configured target host and return a server-side response from an attacker-chosen URL. Users should be aware of the potential i [truncated]