PT-2026-81366 · Rclone · Rclone

·

CVE-2026-79777

·

Published

2026-08-05

·

Updated

2026-08-28

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions rclone versions prior to 1.75.0
Description The RC API includes full Go stack traces in error responses when panics occur. This allows attackers to trigger panics to leak sensitive information, including internal file paths, module versions, goroutine states, and memory addresses.
Recommendations Update rclone to version 1.75.0 or later.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79777
GHSA-GWFQ-86J8-7QHV
GO-2026-6181

Affected Products

Rclone