PT-2026-68328 · Rclone · Rclone
CVE-2026-71309
·
Published
2026-08-05
·
Updated
2026-09-04
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
rclone versions 1.40.0 through 1.74.0
Description
The
serve restic command fails to properly reject URL paths starting with ../ in the WithRemote function within cmd/serve/restic/restic.go. This allows a leading parent path to be passed to GET, HEAD, POST, and DELETE handlers for backends such as WebDAV, FTP, HTTP, Memory, and SFTP. An attacker with access to the REST endpoint can read, create, overwrite, or delete objects outside the operator's configured path if the backend credentials have access to parent or sibling objects.Recommendations
Update to version 1.75.0.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rclone