Link following in rclone - CVE-2026-54572

 

Link following in rclone - CVE-2026-54572

Published: July 9, 2026


Vulnerability identifier: #VU137265
CSH Severity: Medium
CVSS v4: 5.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-54572
CWE-ID: CWE-59
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper link resolution before file access in the local backend link handling in rclone when copying an attacker-controlled remote to a local destination with --links. A remote attacker can provide crafted .rclonelink objects and sibling files to achieve arbitrary file write outside the destination and execute arbitrary code.

User interaction is required to copy data from an untrusted remote while preserving symlinks.


Affected software

rclone

How to mitigate CVE-2026-54572

Install security update from vendor's website.

rclone - update to 1.74.4

External References

Related Security Bulletins