Path traversal in rclone - #VU147302
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to write files outside the intended destination directory.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in the archive/zip backend\'s readZip function when processing crafted zip entry names. A remote attacker can supply a crafted zip archive containing traversal entry names to write files outside the intended destination directory.
User interaction is required to process the crafted archive with rclone copy or sync.