CVE-2026-93987
- EPSS 0.11%
- Veröffentlicht 19.09.2026 11:53:38
- Zuletzt bearbeitet 22.09.2026 20:25:55
rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin. newVolume() in cmd/serve/docker/volume.go computes a volume's mountpoint as filepath.Join(drv.root, name) from the attacker-suppl...
CVE-2026-93986
- EPSS 0.2%
- Veröffentlicht 19.09.2026 11:53:37
- Zuletzt bearbeitet 22.09.2026 20:25:55
rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names. Attackers can craft special names containing forward slashes and parent directory re...
CVE-2026-88018
- EPSS 0.49%
- Veröffentlicht 10.09.2026 16:18:08
- Zuletzt bearbeitet 14.09.2026 20:01:05
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to register any client-chosen...
CVE-2026-88046
- EPSS 0.29%
- Veröffentlicht 10.09.2026 16:14:49
- Zuletzt bearbeitet 15.09.2026 15:17:24
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone core does not reject parent-directory segments in source Object.Remote() values before fs/list, fs/walk, fs/sync, an...
CVE-2026-88045
- EPSS 0.54%
- Veröffentlicht 10.09.2026 16:11:39
- Zuletzt bearbeitet 10.09.2026 19:54:25
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the serve S3 streamed multipart path in cmd/serve/s3/multipart.go passes attacker-controlled contentLength to mult...
CVE-2026-88044
- EPSS 0.49%
- Veröffentlicht 10.09.2026 16:08:14
- Zuletzt bearbeitet 10.09.2026 19:54:25
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 constructors in cm...
CVE-2026-88017
- EPSS 0.23%
- Veröffentlicht 10.09.2026 15:55:15
- Zuletzt bearbeitet 14.09.2026 20:00:53
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.64.0 until 1.75.1, the FTP auth-proxy driver in cmd/serve/ftp/ftp.go stores one obscured password per username in the server-wide use...
CVE-2026-88016
- EPSS 0.2%
- Veröffentlicht 10.09.2026 15:53:39
- Zuletzt bearbeitet 15.09.2026 15:17:24
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, when backend/local runs with --links, a source .rclonelink object can plant a symlink in the destination and later director...
CVE-2026-88015
- EPSS 0.35%
- Veröffentlicht 10.09.2026 15:50:41
- Zuletzt bearbeitet 23.09.2026 20:42:27
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects, and fs.RangeOption.Decode can pass...
CVE-2026-88014
- EPSS 0.14%
- Veröffentlicht 10.09.2026 15:48:32
- Zuletzt bearbeitet 23.09.2026 20:39:36
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.72.0 until 1.75.1, the archive ZIP backend method (*Fs).readZip in backend/archive/zip/zip.go accepts archive/zip.File.Name values fr...