PT-2026-80417 · Go · Github.Com/Rclone/Rclone
Published
2026-08-18
·
Updated
2026-08-18
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In rclone serve restic, the WithRemote middleware fails to properly sanitize URL paths beginning with "../" or containing ".". Because path.Clean preserves leading parent directory components in relative paths, requests with leading traversal sequences bypass validation. On affected backends (such as WebDAV, FTP, SFTP, HTTP, and memory), an attacker with access to the REST endpoint can read, create, overwrite, or delete objects outside the configured root directory.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Github.Com/Rclone/Rclone