Rclone是Rclone团队开源的一款同步文件到各类云存储服务的命令行工具。 Rclone 1.74.4之前版本存在路径遍历漏洞,该漏洞源于解压特制压缩包时未正确处理路径令牌(如../),可能导致文件写入用户所选目标前缀之外。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59733 | 8.8 HIGH | rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an a |
| CVE-2026-54572 | 7.5 HIGH | rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untru |
No comments yet