Zoraxy Authenticated Path Traversal Vulnerability Leading to Remote Code Execution

Vulnerability

A path traversal vulnerability allowing authenticated users to write arbitrary files outside the configuration directory has been identified in Zoraxy versions prior to 3.3.2. This vulnerability exists in the configuration import endpoint, where the sanitization of zip entry names can be bypassed. Exploiting this issue could lead to remote code execution by creating a malicious plugin. The vulnerability is particularly concerning because, if exploited, it could allow for a full host takeover, especially if the Docker socket is mapped.

Impact

Exploitation of this vulnerability allows for arbitrary file writing, which can be leveraged to execute remote code. Given that the Docker socket might be mapped, this could result in a complete takeover of the host system.

Reproduction

To reproduce this vulnerability, an authenticated user can upload a zip file through the configuration import endpoint. The zip file should be crafted to include a payload that exploits the path traversal vulnerability by embedding '../' sequences. Once the malicious zip file is uploaded, the payload can be executed by manipulating the Zoraxy application environment.

Remediation

Users are advised to update to Zoraxy version 3.3.2 or later, where this vulnerability has been patched.

Added: Mar 26, 2026, 8:28 PM
Updated: Mar 26, 2026, 8:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.6
remediation
0.0
relevance
4.7
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.