These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-88046 is a vulnerability in the rclone command-line program that could allow an attacker to escape the configured root directory and access other buckets, shares, or paths reachable by the victim's credential. The issue is fixed in version 1.75.1. Cloud storage administrators and users who utilize rclone for syncing files and directories should assess their exposure and verify their inventory of [truncated]
CVE-2026-88018 is a critical vulnerability in the rclone command-line program used for syncing files and directories with cloud storage providers. An unauthenticated network attacker can exploit this issue to gain unauthorized access to backend systems by choosing an arbitrary access key, signing with an empty secret, and reaching whatever backend the auth-proxy script resolves for that identity. This iss [truncated]
CVE-2026-88017 is a high-severity vulnerability in the rclone command-line program used for syncing files and directories with cloud storage providers. The issue, fixed in version 1.75.1, involves the FTP auth-proxy driver storing obscured passwords in a server-wide map, allowing a later login with the same username but different proxy backend to overwrite the earlier session's credentials. This could ena [truncated]
CVE-2026-88016 is a vulnerability in the rclone command-line program that allows an attacker to apply selected ownership, permissions, modification times, or birth times to a file or directory outside the destination when using the --links and --metadata flags. The issue arises from the MkdirMetadata, writeMetadataToFile, and setTimes operating when Directory.translatedLink=false, allowing os.Chown, os.Ch [truncated]
A denial-of-service vulnerability exists in rclone versions prior to 1.75.1. When using the --links or links=true option with the local backend, an attacker can trigger a panic by providing a Range start larger than the target length of a symlink. This issue is fixed in version 1.75.1. The vulnerability allows an attacker to cause a denial-of-service condition by exploiting the panic triggered by a specia [truncated]
rclone, a command-line program for syncing files and directories across different cloud storage providers, is vulnerable to a path traversal issue. This vulnerability, present in versions 1.72.0 through 1.75.1, allows attackers to write outside the selected destination on certain backends by manipulating archive/zip.File.Name values from untrusted central directories. The issue arises because the program' [truncated]
CVE-2026-88013 is a vulnerability in the rclone command-line program that allows custom secrets to be resent to an untrusted destination during normal use. The issue arises from the HTTP backend attaching headers configured through --http-headers or headers= to requests, while its fshttp.NewClient client follows redirects without a backend-specific http.Client.CheckRedirect policy. This can cause sensitiv [truncated]
rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files. This vulnerability can lead to potential privilege escalation if rclone runs as root or to the service account user. The issue arises when copying with metadata preservation from an untrusted remote, enabling [truncated]
rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can intercept plaintext HTTP traffic to capture AWS STS session tokens sent in request headers. This vulnerability allows for potential unauthorized access to AWS resources and impacts cloud security and access control. Defenders should assess exposure and p [truncated]
CVE-2026-79781 is a path traversal vulnerability in rclone serve s3 before version 1.74.4. This vulnerability allows attackers to read and overwrite root-level files by using dot-dot segments in S3 object keys. The vulnerability was published on 2026-08-25T16:17:30.080Z and last modified on 2026-09-10T20:46:19.780Z. Affected product deployments should be verified, and owners should prioritize updates to v [truncated]
rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, allowing credentials to be preserved across scheme or host changes. This oversight enables attackers observing network traffic from a trusted endpoint to capture reusable IBM IAM tokens on same-host HTTPS-to-HTTP downgrades or SSE-C keys on cross-origin redirects, thereby gaining access to [truncated]
rclone versions before v1.75.0 are vulnerable to credential exposure via HTTP redirects. An on-path attacker can capture and reuse credentials to perform WebDAV operations. This vulnerability affects rclone deployments using WebDAV operations, particularly those with Basic authorization and Cookie headers. Defenders should assess exposure and prioritize upgrading to v1.75.0 or later to prevent credential [truncated]
A denial of service vulnerability exists in rclone before v1.75.0 within the WebDAV TUS creation handler. This vulnerability allows a malicious or compromised configured endpoint to reset connections during TUS uploads, triggering a panic that terminates unrecovered goroutines and halts unrelated work in long-lived processes. The vulnerability can cause service disruption and impact long-lived processes d [truncated]
rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses. This vulnerability may impact rclone deployments, particularly those with exposed RC API endpoints. Defenders should assess exposure and prioritize verification and remediation efforts to prevent [truncated]
CVE-2026-79776 is a vulnerability in rclone before version 1.75.0 where the pprof debug handler is mounted as its own router route, bypassing the authentication rule in the main handler. This allows unauthenticated access to the /debug/pprof/cmdline endpoint to retrieve the full process argv including backend credentials. The vulnerability has a medium severity and can lead to potential exposure of backen [truncated]
The CVE-2026-79775 record details a critical vulnerability in rclone versions from v1.72.0 to v1.74.4. This vulnerability affects the archive backend's SquashFS parser, which fails to validate attacker-controlled superblock and metadata values. Consequently, an attacker can craft malicious SquashFS images that trigger denial-of-service conditions, including crashes or sustained CPU consumption. The vulner [truncated]
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 until v1.75.0, the local backend in backend/local/local.go relies on the configurable filename encoder to prevent remote filename data from becoming operating-system path syntax, so a local destination using Slash, None, Raw, or on Windows an encoding that preserves backslash can deco [truncated]
rclone's command-line program used to sync files and directories to and from different cloud storage providers had a vulnerability prior to v1.75.0. The issue allowed an attacker to inject PowerShell commands via a specially crafted filename when server-side hashing was invoked, potentially leading to code execution as the victim SSH account. This vulnerability was addressed in version 1.75.0.
CVE-2026-71311 is a medium-severity vulnerability in the rclone command-line program used for syncing files and directories with cloud storage providers. A malicious FTP filename can inject an independent authenticated FTP command when a victim copies or syncs to a more-privileged FTP destination. This issue arises from improper handling of FTP filenames in the rclone backend, specifically in the ftp.go f [truncated]
rclone, a command-line program for syncing files and directories with cloud storage providers, had a vulnerability prior to version 1.75.0. The shared HTTP CONNECT helper in lib/proxy/http.go could parse oversized proxy CONNECT responses, leading to potential memory exhaustion and process failure when using FTP and SFTP proxy connections. This issue was fixed in version 1.75.0.
CVE-2026-59733 is a high-severity vulnerability in Rclone, a command-line program for syncing files and directories with cloud storage providers. The issue, now patched in version 1.74.4, involves a path traversal vulnerability in the `rclone serve restic --private-repos` command. An authenticated user could exploit this vulnerability to read, overwrite, or delete another user's private repository on cert [truncated]
Rclone's archive extract feature can write files outside the user-selected destination prefix when extracting a crafted archive containing parent path components like ../. This issue allows creation or overwrite of sibling objects in the same bucket or path scope. The vulnerability is fixed in Rclone version 1.74.4. This issue has a CVSS score of 5, indicating medium severity. The vulnerability can be exp [truncated]
CVE-2026-49980 is a critical vulnerability in Rclone, a command-line program for syncing files and directories with cloud storage providers. The vulnerability allows unauthenticated GET and HEAD requests to execute commands as the rclone process user. This issue was introduced in version 1.46.0 and fixed in version 1.74.3. The vulnerability has a CVSS score of 9.8 and is considered critical. Rclone users [truncated]
Rclone versions 1.48.0 through 1.73.4 contain a critical unauthenticated remote code execution vulnerability in the RC (remote control) endpoint `operations/fsinfo`. The endpoint lacks authentication requirements and accepts attacker-controlled `fs` parameters that support inline backend definitions. An unauthenticated attacker can instantiate a malicious WebDAV backend with a crafted `bearer_token_comman [truncated]
CVE-2026-41176 is a critical vulnerability in Rclone, a command-line program for syncing files and directories with cloud storage providers. The vulnerability exists in the RC endpoint `options/set`, which is exposed without requiring authentication. This allows an unauthenticated attacker to mutate global runtime configuration, including the RC option block itself. Specifically, an attacker can set `rc.N [truncated]