PT-2026-71633 · Rsync · Rsync
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
rsync versions prior to 3.5.0
Description
An arbitrary file write issue exists where attackers can write files outside the intended destination tree. This occurs by specifying an absolute path through the
--temp-dir or --link-dest options, which bypasses the rename-confinement logic. This allows attacker-controlled values to write files to any location accessible to the rsync process.Recommendations
Update rsync to version 3.5.0 or later.
Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rsync