PT-2026-68330 · Rclone+1 · Rclone+1

CVE-2026-71311

·

Published

2026-08-05

·

Updated

2026-09-04

CVSS v3.1

6.4

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions rclone versions prior to 1.75.0
Description A flaw in the FTP filename encoding within backend/ftp/ftp.go allows the restoration of raw Carriage Return (CR) and Line Feed (LF) characters. These characters can be placed immediately before an attacker-controlled path is interpolated into the line-oriented FTP control channel. Because the github.com/jlaffaye/ftp library formats arguments through textproto.Conn.Cmd without rejecting CR or LF, an attacker can use a specially crafted filename to inject independent authenticated FTP commands. This occurs when a user copies or syncs files to a more-privileged FTP destination.
Recommendations Update rclone to version 1.75.0.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-RCLONE-2026-71311
CVE-2026-71311
GHSA-8C48-Q9WJ-3W37
GO-2026-6187
OPENSUSE-SU-2026:21761-1

Affected Products

Github.Com/Jlaffaye/Ftp
Rclone