Rclone是Rclone团队开源的一款同步文件到各类云存储服务的命令行工具。 Rclone 1.74.4之前版本存在后置链接漏洞,该漏洞源于在使用-l/--links参数时,将符号链接序列化为.rclonelink文本对象并在本地目标上重新创建时未验证目标,允许攻击者控制的远程服务器植入逃逸符号链接,导致后续对象写入落入目标之外并包含攻击者选择的内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-59733 | 8.8 HIGH | rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an a |
| CVE-2026-59732 | 5.0 MEDIUM | rclone archive extract allows S3 destination prefix escape via crafted archive paths |
No comments yet