在 rclone 1.74.4 版本之前的 服务中存在一个路径遍历漏洞。攻击者可以通过在 S3 对象键(object key)中使用“../”等双点段,读取并覆盖位于根目录下的文件。例如,攻击者可以发送包含类似 的对象键的请求,从而绕过存储桶命名空间的限制,访问并操作 serve 根目录下的敏感文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-79775 | 6.5 MEDIUM | rclone Archive Backend SquashFS Parser Denial of Service |
| CVE-2026-79780 | 5.3 MEDIUM | rclone before v1.75.0 Credential Exposure via S3 Redirect |
| CVE-2026-79779 | 5.3 MEDIUM | rclone before v1.75.0 WebDAV Credential Exposure via HTTPS-to-HTTP Redirect |
| CVE-2026-79778 | 5.3 MEDIUM | rclone before v1.75.0 Denial of Service via TUS nil-response panic |
| CVE-2026-79776 | 5.3 MEDIUM | rclone before 1.75.0 Authentication Bypass via pprof |
| CVE-2026-79783 | 3.6 LOW | rclone before 1.74.4 Privilege Escalation via setuid Metadata |
| CVE-2026-79782 | 3.1 LOW | rclone before 1.74.4 Security Token Disclosure via HTTPS to HTTP Redirect |
| CVE-2026-79777 | 2.7 LOW | rclone before v1.75.0 Information Disclosure via RC API |
No comments yet