GHSA-rq8c-9999-42w5HighCVSS 7.5

ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries...

Published
September 15, 2026
Last Modified
September 15, 2026

🔗 CVE IDs covered (1)

📋 Description

ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared base directory, bypassing the intended access restrictions.

🔗 References (6)