CVE-2026-71313
- EPSS 0.25%
- Veröffentlicht 05.08.2026 21:16:59
- Zuletzt bearbeitet 09.09.2026 20:50:00
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 until v1.75.0, the local backend in backend/local/local.go relies on the configurable filename encoder to prevent remote filena...
- EPSS 0.28%
- Veröffentlicht 05.08.2026 20:37:49
- Zuletzt bearbeitet 09.09.2026 20:50:00
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscapeShellPath es...
CVE-2026-71311
- EPSS 0.24%
- Veröffentlicht 05.08.2026 20:33:32
- Zuletzt bearbeitet 09.09.2026 20:50:00
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, a valid but nondefault FTP filename encoding in backend/ftp/ftp.go can restore raw CR/LF immediately before an attacker-con...
CVE-2026-71310
- EPSS 0.37%
- Veröffentlicht 05.08.2026 20:17:14
- Zuletzt bearbeitet 09.09.2026 20:50:00
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, the shared HTTP CONNECT helper in lib/proxy/http.go parses proxy CONNECT responses with http.ReadResponse over an unrestric...
CVE-2026-71309
- EPSS 0.31%
- Veröffentlicht 05.08.2026 20:13:30
- Zuletzt bearbeitet 09.09.2026 20:50:00
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.0 until 1.75.0, rclone serve restic does not correctly reject URL paths beginning with ../ in cmd/serve/restic/restic.go WithRemot...
CVE-2026-59733
- EPSS 0.42%
- Veröffentlicht 14.07.2026 21:38:37
- Zuletzt bearbeitet 29.07.2026 20:17:04
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path segment while building the backend ob...
CVE-2026-54572
- EPSS 0.31%
- Veröffentlicht 14.07.2026 21:37:41
- Zuletzt bearbeitet 17.07.2026 03:13:56
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks as .rclonelink text objects and recreates them on a local destination without v...
- EPSS 0.21%
- Veröffentlicht 14.07.2026 21:36:21
- Zuletzt bearbeitet 21.07.2026 16:17:18
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone archive extract can write extracted files outside the user-selected destination prefix when extracting a crafted arc...
CVE-2026-49980
- EPSS 0.74%
- Veröffentlicht 24.06.2026 17:52:33
- Zuletzt bearbeitet 07.08.2026 12:18:00
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticated GET and HEAD requests to paths of the form: /[remote:path]/object. T...
CVE-2026-41179
- EPSS 8.59%
- Veröffentlicht 23.04.2026 00:03:36
- Zuletzt bearbeitet 15.07.2026 02:21:14
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting in version 1.48.0 and prior to version 1.73.5, the RC endpoint `operations/fsinfo` is exposed without `AuthRequired: true` and acce...