PT-2026-95824 · Rclone · Rclone
CVSS v4.0
4.6
Medium
| Vector | AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
rclone versions 1.56.0 through 1.75.0
Description
A path traversal issue exists in the
rclone serve docker volume plugin. The newVolume() function in cmd/serve/docker/volume.go calculates a volume mountpoint using the name variable from a Docker VolumeDriver.Create request without verifying that the resulting path remains within the intended root directory. Subsequently, the checkMountpoint() function creates this directory using file.MkdirAll before mounting. An attacker providing a name containing path traversal sequences (e.g., ../../../../../../etc) can force the privileged rclone process to create a directory and mount a remote filesystem at an arbitrary host path, potentially shadowing or disrupting system directories. Additionally, the Volume.restoreState() function lacks similar validation when reloading persisted volume state.Recommendations
Update to version 1.75.1.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rclone