Path traversal in rclone - #VU147296
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to write outside the listed directory.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in multiple backend listing-response handlers when processing server or third-party listing responses containing crafted object names. A remote attacker can create a crafted shared object containing path traversal sequences to write outside the listed directory.
User interaction is required to initiate processing of the crafted listing.