Path traversal in rclone - #VU147296

 

Path traversal in rclone - #VU147296

Published: September 7, 2026


Vulnerability identifier: #VU147296
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to write outside the listed directory.

The vulnerability exists due to improper limitation of a pathname to a restricted directory in multiple backend listing-response handlers when processing server or third-party listing responses containing crafted object names. A remote attacker can create a crafted shared object containing path traversal sequences to write outside the listed directory.

User interaction is required to initiate processing of the crafted listing.


Affected software

rclone

Remediation

Install security update from vendor's website.

rclone - update to 1.75.1

External References

Related Security Bulletins