Path traversal in rclone - #VU147302

 

Path traversal in rclone - #VU147302

Published: September 7, 2026


Vulnerability identifier: #VU147302
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to write files outside the intended destination directory.

The vulnerability exists due to improper limitation of a pathname to a restricted directory in the archive/zip backend\'s readZip function when processing crafted zip entry names. A remote attacker can supply a crafted zip archive containing traversal entry names to write files outside the intended destination directory.

User interaction is required to process the crafted archive with rclone copy or sync.


Affected software

rclone

Remediation

Install security update from vendor's website.

rclone - update to 1.75.1

External References

Related Security Bulletins