These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T21:16:59.003Z and has not been modified since then. The vulnerability affects rclone versions prior to 1.75.0, allowing an attacker to create or overwrite files outside the selected destination directory due to a path traversal issue. Users of rclone, especially those using versions prior to 1.75 [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T21:16:58.867Z and has not been modified since then. This vulnerability affects rclone versions prior to v1.75.0, where remote SFTP paths are interpolated into PowerShell hash commands without proper escaping of single-quote delimiters. An attacker-controlled filename can terminate the intended pa [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T21:16:58.727Z and has not been modified since then. The vulnerability affects rclone versions prior to 1.75.0, specifically in the FTP functionality. A valid but nondefault FTP filename encoding can restore raw CR/LF immediately before an attacker-controlled path is interpolated into the line-ori [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T21:16:58.573Z and has not been modified since then. The vulnerability affects rclone's shared HTTP CONNECT helper, allowing a malicious proxy to cause memory exhaustion via oversized headers in HTTP CONNECT responses, impacting FTP and SFTP proxy connections. This issue is fixed in version 1.75.0 [truncated]
CVE-2026-59733 is a high-severity vulnerability in Rclone, a command-line program for syncing files and directories with cloud storage providers. The issue, now patched in version 1.74.4, involves a path traversal vulnerability in the `rclone serve restic --private-repos` command. An authenticated user could exploit this vulnerability to read, overwrite, or delete another user's private repository on cert [truncated]
Rclone's archive extract feature can write files outside the user-selected destination prefix when extracting a crafted archive containing parent path components like ../. This issue allows creation or overwrite of sibling objects in the same bucket or path scope. The vulnerability is fixed in Rclone version 1.74.4. This issue has a CVSS score of 5, indicating medium severity. The vulnerability can be exp [truncated]
CVE-2026-49980 is a critical vulnerability in Rclone, a command-line program for syncing files and directories with cloud storage providers. The vulnerability allows unauthenticated GET and HEAD requests to execute commands as the rclone process user. This issue was introduced in version 1.46.0 and fixed in version 1.74.3. The vulnerability has a CVSS score of 9.8 and is considered critical. Rclone users [truncated]
Rclone versions 1.48.0 through 1.73.4 contain a critical unauthenticated remote code execution vulnerability in the RC (remote control) endpoint `operations/fsinfo`. The endpoint lacks authentication requirements and accepts attacker-controlled `fs` parameters that support inline backend definitions. An unauthenticated attacker can instantiate a malicious WebDAV backend with a crafted `bearer_token_comman [truncated]
CVE-2026-41176 is a critical vulnerability in Rclone, a command-line program for syncing files and directories with cloud storage providers. The vulnerability exists in the RC endpoint `options/set`, which is exposed without requiring authentication. This allows an unauthenticated attacker to mutate global runtime configuration, including the RC option block itself. Specifically, an attacker can set `rc.N [truncated]