Path traversal in rclone - #VU147300
Published: September 7, 2026
Vulnerability details
The vulnerability allows a local privileged user to mount a remote filesystem at an arbitrary host path, disrupting or shadowing system directories.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in Volume.restoreState when restoring persisted volume state. A local privileged user can supply persisted state containing an escaped mountpoint to mount a remote filesystem at an arbitrary host path, disrupting or shadowing system directories.
A persisted state file written by a vulnerable instance or restored from an untrusted backup or copy can contain an escaped mountpoint.