PT-2026-95823 · Rclone · Rclone

·

CVE-2026-93986

·

Published

2026-09-19

·

Updated

2026-09-29

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions rclone versions prior to 1.75.1
Description The software fails to confine names from server and third-party listing responses to the listed directory. This allows path traversal sequences in object names, where attackers can craft special names containing forward slashes and parent directory references to potentially write outside the destination root. However, downstream protections in the local backend currently block actual file escape.
Recommendations Update rclone to version 1.75.1 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-RCLONE-2026-93986
CVE-2026-93986
GHSA-3VXH-3PCX-9M8Q

Affected Products

Rclone