Description

Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. Prior to version 3.3.2, an authenticated path traversal vulnerability in the configuration import endpoint allows an authenticated user to write arbitrary files outside the config directory, which can lead to RCE by creating a plugin. Version 3.3.2 patches the issue.

INFO

Published Date :

2026-03-26T19:26:32.646Z

Last Modified :

2026-03-27T19:48:28.328Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-33529 vulnerability.

Vendors Products
Tobychui
  • Zoraxy

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact