PT-2026-95823 · Rclone · Rclone
CVSS v3.1
3.1
Low
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
rclone versions prior to 1.75.1
Description
The software fails to confine names from server and third-party listing responses to the listed directory. This allows path traversal sequences in object names, where attackers can craft special names containing forward slashes and parent directory references to potentially write outside the destination root. However, downstream protections in the local backend currently block actual file escape.
Recommendations
Update rclone to version 1.75.1 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rclone