PT-2026-68330 · Rclone+1 · Rclone+1
CVE-2026-71311
·
Published
2026-08-05
·
Updated
2026-09-04
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
rclone versions prior to 1.75.0
Description
A flaw in the FTP filename encoding within
backend/ftp/ftp.go allows the restoration of raw Carriage Return (CR) and Line Feed (LF) characters. These characters can be placed immediately before an attacker-controlled path is interpolated into the line-oriented FTP control channel. Because the github.com/jlaffaye/ftp library formats arguments through textproto.Conn.Cmd without rejecting CR or LF, an attacker can use a specially crafted filename to inject independent authenticated FTP commands. This occurs when a user copies or syncs files to a more-privileged FTP destination.Recommendations
Update rclone to version 1.75.0.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Github.Com/Jlaffaye/Ftp
Rclone