{"id":"GHSA-74m3-9qvm-rp9h","summary":"zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write","details":"**Summary**\nThe zrok WebDAV drive backend (davServer.Dir) restricts path traversal through lexical normalization but does not prevent symlink following. When a symbolic link inside the shared DriveRoot points to a location outside that root, remote WebDAV consumers can read files and—on shares without OS-level permission restrictions—write or overwrite files anywhere on the host filesystem accessible to the zrok process.\n\n- Attack Vector: Network — exploitation is performed entirely over the WebDAV endpoint; the attacker issues HTTP requests to the public zrok share URL.\n- Attack Complexity: High — a precondition outside the attacker's direct control must hold: a symlink pointing outside DriveRoot must already exist within it (created locally, not via WebDAV).\n- Privileges Required: None — zrok share public --backend-mode drive exposes the WebDAV endpoint with no authentication by default.\n- User Interaction: None — once the symlink precondition is met, exploitation requires no user interaction.\n- Scope: Changed — the vulnerability allows an attacker to escape the WebDAV root (the security boundary) and access the broader host filesystem.\n- Confidentiality Impact: High — arbitrary files readable by the zrok process can be retrieved.\n- Integrity Impact: High — the WebDAV PUT handler opens files with O_RDWR|O_CREATE|O_TRUNC, meaning symlink targets outside DriveRoot can be overwritten (e.g. ~/.ssh/authorized_keys).\n- Availability Impact: None — no direct availability impact.\n\nAffected Components\n\n- drives/davServer/file.go — Dir.OpenFile (line 140), Dir.Stat (line 176), Dir.Mkdir (line 133), Dir.RemoveAll (line 151)\n- endpoints/drive/backend.go — NewBackend (line 51–52)","aliases":["CVE-2026-42275","GO-2026-5203"],"modified":"2026-06-25T19:56:14.959291901Z","published":"2026-04-25T23:34:35Z","database_specific":{"github_reviewed_at":"2026-04-25T23:34:35Z","nvd_published_at":"2026-05-08T04:16:22Z","cwe_ids":["CWE-22","CWE-61"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/openziti/zrok/security/advisories/GHSA-74m3-9qvm-rp9h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42275"},{"type":"WEB","url":"https://github.com/openziti/zrok/commit/459bcfc1e121decae1b1d11c37ad94e4ed5bbf2e"},{"type":"PACKAGE","url":"https://github.com/openziti/zrok"},{"type":"WEB","url":"https://github.com/openziti/zrok/releases/tag/v2.0.2"}],"affected":[{"package":{"name":"github.com/openziti/zrok","ecosystem":"Go","purl":"pkg:golang/github.com/openziti/zrok"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.1.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-74m3-9qvm-rp9h/GHSA-74m3-9qvm-rp9h.json"}},{"package":{"name":"github.com/openziti/zrok/v2","ecosystem":"Go","purl":"pkg:golang/github.com/openziti/zrok/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.0.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-74m3-9qvm-rp9h/GHSA-74m3-9qvm-rp9h.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"}]}