PatchSiren

rclone CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM rclone CVE published 2026-09-10

CVE-2026-88046

CVE-2026-88046 is a vulnerability in the rclone command-line program that could allow an attacker to escape the configured root directory and access other buckets, shares, or paths reachable by the victim's credential. The issue is fixed in version 1.75.1. Cloud storage administrators and users who utilize rclone for syncing files and directories should assess their exposure and verify their inventory of [truncated]

CRITICAL rclone CVE published 2026-09-10

CVE-2026-88018

CVE-2026-88018 is a critical vulnerability in the rclone command-line program used for syncing files and directories with cloud storage providers. An unauthenticated network attacker can exploit this issue to gain unauthorized access to backend systems by choosing an arbitrary access key, signing with an empty secret, and reaching whatever backend the auth-proxy script resolves for that identity. This iss [truncated]

HIGH rclone CVE published 2026-09-10

CVE-2026-88017

CVE-2026-88017 is a high-severity vulnerability in the rclone command-line program used for syncing files and directories with cloud storage providers. The issue, fixed in version 1.75.1, involves the FTP auth-proxy driver storing obscured passwords in a server-wide map, allowing a later login with the same username but different proxy backend to overwrite the earlier session's credentials. This could ena [truncated]

HIGH rclone CVE published 2026-09-10

CVE-2026-88016

CVE-2026-88016 is a vulnerability in the rclone command-line program that allows an attacker to apply selected ownership, permissions, modification times, or birth times to a file or directory outside the destination when using the --links and --metadata flags. The issue arises from the MkdirMetadata, writeMetadataToFile, and setTimes operating when Directory.translatedLink=false, allowing os.Chown, os.Ch [truncated]

MEDIUM rclone CVE published 2026-09-10

CVE-2026-88015

A denial-of-service vulnerability exists in rclone versions prior to 1.75.1. When using the --links or links=true option with the local backend, an attacker can trigger a panic by providing a Range start larger than the target length of a symlink. This issue is fixed in version 1.75.1. The vulnerability allows an attacker to cause a denial-of-service condition by exploiting the panic triggered by a specia [truncated]

MEDIUM rclone CVE published 2026-09-10

CVE-2026-88014

rclone, a command-line program for syncing files and directories across different cloud storage providers, is vulnerable to a path traversal issue. This vulnerability, present in versions 1.72.0 through 1.75.1, allows attackers to write outside the selected destination on certain backends by manipulating archive/zip.File.Name values from untrusted central directories. The issue arises because the program' [truncated]

LOW rclone CVE published 2026-09-10

CVE-2026-88013

CVE-2026-88013 is a vulnerability in the rclone command-line program that allows custom secrets to be resent to an untrusted destination during normal use. The issue arises from the HTTP backend attaching headers configured through --http-headers or headers= to requests, while its fshttp.NewClient client follows redirects without a backend-specific http.Client.CheckRedirect policy. This can cause sensitiv [truncated]

LOW rclone CVE published 2026-08-25

CVE-2026-79783

rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files. This vulnerability can lead to potential privilege escalation if rclone runs as root or to the service account user. The issue arises when copying with metadata preservation from an untrusted remote, enabling [truncated]

CRITICAL rclone CVE published 2026-08-25

CVE-2026-79782

rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can intercept plaintext HTTP traffic to capture AWS STS session tokens sent in request headers. This vulnerability allows for potential unauthorized access to AWS resources and impacts cloud security and access control. Defenders should assess exposure and p [truncated]

MEDIUM rclone CVE published 2026-08-25

CVE-2026-79781

CVE-2026-79781 is a path traversal vulnerability in rclone serve s3 before version 1.74.4. This vulnerability allows attackers to read and overwrite root-level files by using dot-dot segments in S3 object keys. The vulnerability was published on 2026-08-25T16:17:30.080Z and last modified on 2026-09-10T20:46:19.780Z. Affected product deployments should be verified, and owners should prioritize updates to v [truncated]

MEDIUM rclone CVE published 2026-08-25

CVE-2026-79780

rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, allowing credentials to be preserved across scheme or host changes. This oversight enables attackers observing network traffic from a trusted endpoint to capture reusable IBM IAM tokens on same-host HTTPS-to-HTTP downgrades or SSE-C keys on cross-origin redirects, thereby gaining access to [truncated]

MEDIUM rclone CVE published 2026-08-25

CVE-2026-79779

rclone versions before v1.75.0 are vulnerable to credential exposure via HTTP redirects. An on-path attacker can capture and reuse credentials to perform WebDAV operations. This vulnerability affects rclone deployments using WebDAV operations, particularly those with Basic authorization and Cookie headers. Defenders should assess exposure and prioritize upgrading to v1.75.0 or later to prevent credential [truncated]

MEDIUM rclone CVE published 2026-08-25

CVE-2026-79778

A denial of service vulnerability exists in rclone before v1.75.0 within the WebDAV TUS creation handler. This vulnerability allows a malicious or compromised configured endpoint to reset connections during TUS uploads, triggering a panic that terminates unrecovered goroutines and halts unrelated work in long-lived processes. The vulnerability can cause service disruption and impact long-lived processes d [truncated]

MEDIUM rclone CVE published 2026-08-25

CVE-2026-79777

rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses. This vulnerability may impact rclone deployments, particularly those with exposed RC API endpoints. Defenders should assess exposure and prioritize verification and remediation efforts to prevent [truncated]

MEDIUM rclone CVE published 2026-08-25

CVE-2026-79776

CVE-2026-79776 is a vulnerability in rclone before version 1.75.0 where the pprof debug handler is mounted as its own router route, bypassing the authentication rule in the main handler. This allows unauthenticated access to the /debug/pprof/cmdline endpoint to retrieve the full process argv including backend credentials. The vulnerability has a medium severity and can lead to potential exposure of backen [truncated]

HIGH rclone CVE published 2026-08-25

CVE-2026-79775

The CVE-2026-79775 record details a critical vulnerability in rclone versions from v1.72.0 to v1.74.4. This vulnerability affects the archive backend's SquashFS parser, which fails to validate attacker-controlled superblock and metadata values. Consequently, an attacker can craft malicious SquashFS images that trigger denial-of-service conditions, including crashes or sustained CPU consumption. The vulner [truncated]

MEDIUM rclone CVE published 2026-08-05

CVE-2026-71313

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 until v1.75.0, the local backend in backend/local/local.go relies on the configurable filename encoder to prevent remote filename data from becoming operating-system path syntax, so a local destination using Slash, None, Raw, or on Windows an encoding that preserves backslash can deco [truncated]

HIGH rclone CVE published 2026-08-05

CVE-2026-71312

rclone's command-line program used to sync files and directories to and from different cloud storage providers had a vulnerability prior to v1.75.0. The issue allowed an attacker to inject PowerShell commands via a specially crafted filename when server-side hashing was invoked, potentially leading to code execution as the victim SSH account. This vulnerability was addressed in version 1.75.0.

MEDIUM rclone CVE published 2026-08-05

CVE-2026-71311

CVE-2026-71311 is a medium-severity vulnerability in the rclone command-line program used for syncing files and directories with cloud storage providers. A malicious FTP filename can inject an independent authenticated FTP command when a victim copies or syncs to a more-privileged FTP destination. This issue arises from improper handling of FTP filenames in the rclone backend, specifically in the ftp.go f [truncated]

MEDIUM rclone CVE published 2026-08-05

CVE-2026-71310

rclone, a command-line program for syncing files and directories with cloud storage providers, had a vulnerability prior to version 1.75.0. The shared HTTP CONNECT helper in lib/proxy/http.go could parse oversized proxy CONNECT responses, leading to potential memory exhaustion and process failure when using FTP and SFTP proxy connections. This issue was fixed in version 1.75.0.

HIGH rclone CVE published 2026-07-14

CVE-2026-59733

CVE-2026-59733 is a high-severity vulnerability in Rclone, a command-line program for syncing files and directories with cloud storage providers. The issue, now patched in version 1.74.4, involves a path traversal vulnerability in the `rclone serve restic --private-repos` command. An authenticated user could exploit this vulnerability to read, overwrite, or delete another user's private repository on cert [truncated]

MEDIUM rclone CVE published 2026-07-14

CVE-2026-59732

Rclone's archive extract feature can write files outside the user-selected destination prefix when extracting a crafted archive containing parent path components like ../. This issue allows creation or overwrite of sibling objects in the same bucket or path scope. The vulnerability is fixed in Rclone version 1.74.4. This issue has a CVSS score of 5, indicating medium severity. The vulnerability can be exp [truncated]

CRITICAL rclone CVE published 2026-06-24

CVE-2026-49980

CVE-2026-49980 is a critical vulnerability in Rclone, a command-line program for syncing files and directories with cloud storage providers. The vulnerability allows unauthenticated GET and HEAD requests to execute commands as the rclone process user. This issue was introduced in version 1.46.0 and fixed in version 1.74.3. The vulnerability has a CVSS score of 9.8 and is considered critical. Rclone users [truncated]

CRITICAL rclone CVE published 2026-04-23

CVE-2026-41179

Rclone versions 1.48.0 through 1.73.4 contain a critical unauthenticated remote code execution vulnerability in the RC (remote control) endpoint `operations/fsinfo`. The endpoint lacks authentication requirements and accepts attacker-controlled `fs` parameters that support inline backend definitions. An unauthenticated attacker can instantiate a malicious WebDAV backend with a crafted `bearer_token_comman [truncated]

CRITICAL rclone CVE published 2026-04-23

CVE-2026-41176

CVE-2026-41176 is a critical vulnerability in Rclone, a command-line program for syncing files and directories with cloud storage providers. The vulnerability exists in the RC endpoint `options/set`, which is exposed without requiring authentication. This allows an unauthenticated attacker to mutate global runtime configuration, including the RC option block itself. Specifically, an attacker can set `rc.N [truncated]