Path Traversal Vulnerability in CloakBrowser Affecting CloakHQ
CVE-2026-45727
8.8HIGH
What is CVE-2026-45727?
CloakBrowser, a tool designed to bypass bot detection, is affected by a path traversal vulnerability that allows unauthenticated attackers to exploit the cloakserve CDP multiplexer prior to version 0.3.28. By supplying a manipulated fingerprint query parameter, attackers can navigate the filesystem, potentially leading to unauthorized access and deletion of arbitrary directories. Additionally, the service's default binding to 0.0.0.0 makes it accessible over the network, further increasing the risk. This vulnerability has been addressed in version 0.3.28.
Affected Version(s)
CloakBrowser < 0.3.28
