Path Traversal Vulnerability in CloakBrowser Affecting CloakHQ
CVE-2026-45727

8.8HIGH

Key Information:

Vendor

Cloakhq

Vendor
CVE Published:
1 June 2026

What is CVE-2026-45727?

CloakBrowser, a tool designed to bypass bot detection, is affected by a path traversal vulnerability that allows unauthenticated attackers to exploit the cloakserve CDP multiplexer prior to version 0.3.28. By supplying a manipulated fingerprint query parameter, attackers can navigate the filesystem, potentially leading to unauthorized access and deletion of arbitrary directories. Additionally, the service's default binding to 0.0.0.0 makes it accessible over the network, further increasing the risk. This vulnerability has been addressed in version 0.3.28.

Affected Version(s)

CloakBrowser < 0.3.28

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.