PT-2026-81372 · Rclone · Rclone
CVSS v3.1
3.6
Low
| Vector | AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
rclone versions prior to 1.74.4
Description
The local backend fails to mask special permission bits when applying source-supplied mode metadata. This allows an attacker to set setuid or setgid bits on files they control. When copying files with metadata preservation from an untrusted remote source, an attacker can plant a setuid binary to escalate privileges to root if the process runs as root, or to the associated service account user.
Recommendations
Update rclone to version 1.74.4 or later.
Exploit
Fix
LPE
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rclone