CVE-2026-40302 is a stored cross-site scripting (XSS) vulnerability in zrok versions prior to 2.0.1. The vulnerability exists in the proxyUi template engine, which uses Go's text/template instead of html/template, failing to escape HTML characters. An attacker can inject malicious JavaScript through the refreshInterval query parameter in GitHub OAuth callback handlers, affecting both publicProxy and dynamicProxy components. The vulnerability has a CVSS score of 6.1 (Medium severity) with a network-based attack vector requiring low complexity and user interaction. The attack is capable of achieving limited confidentiality and integrity impact, though availability is not affected. The scope is changed, meaning the vulnerable component can impact resources beyond its security scope. There is currently no evidence of active exploitation in the wild, and the vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog. Community attention appears minimal, with an EPSS score of 0.0001 indicating low probability of exploitation. The patch is available in version 2.0.1, and users should upgrade immediately to remediate this XSS risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.1CPE matchmatch criteria | cpe:2.3:a:netfoundry:zrok:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.