PT-2026-95824 · Rclone · Rclone

·

CVE-2026-93987

·

Published

2026-09-19

·

Updated

2026-09-29

CVSS v4.0

4.6

Medium

VectorAV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions rclone versions 1.56.0 through 1.75.0
Description A path traversal issue exists in the rclone serve docker volume plugin. The newVolume() function in cmd/serve/docker/volume.go calculates a volume mountpoint using the name variable from a Docker VolumeDriver.Create request without verifying that the resulting path remains within the intended root directory. Subsequently, the checkMountpoint() function creates this directory using file.MkdirAll before mounting. An attacker providing a name containing path traversal sequences (e.g., ../../../../../../etc) can force the privileged rclone process to create a directory and mount a remote filesystem at an arbitrary host path, potentially shadowing or disrupting system directories. Additionally, the Volume.restoreState() function lacks similar validation when reloading persisted volume state.
Recommendations Update to version 1.75.1.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-RCLONE-2026-93987
CVE-2026-93987
GHSA-P6VX-HF7P-98J6

Affected Products

Rclone