在 rclone 1.74.4 版本之前,在使用本地后端(local backend)应用由源提供的模式元数据(mode metadata)时,未能正确屏蔽特殊权限位(special permission bits),攻击者从而可以在其控制的文件上设置 setuid/setgid 位。当从不受信任的远程源进行带有元数据保留的复制操作时,攻击者可以植入一个 setuid 二进制文件;若 rclone 以 root 权限运行,则该文件可导致权限提升至 root;否则,权限可提升至服务账户用户(service accou
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-79781 | 6.5 MEDIUM | rclone serve s3 Path Traversal via dot-dot object keys |
| CVE-2026-79775 | 6.5 MEDIUM | rclone Archive Backend SquashFS Parser Denial of Service |
| CVE-2026-79780 | 5.3 MEDIUM | rclone before v1.75.0 Credential Exposure via S3 Redirect |
| CVE-2026-79779 | 5.3 MEDIUM | rclone before v1.75.0 WebDAV Credential Exposure via HTTPS-to-HTTP Redirect |
| CVE-2026-79778 | 5.3 MEDIUM | rclone before v1.75.0 Denial of Service via TUS nil-response panic |
| CVE-2026-79776 | 5.3 MEDIUM | rclone before 1.75.0 Authentication Bypass via pprof |
| CVE-2026-79782 | 3.1 LOW | rclone before 1.74.4 Security Token Disclosure via HTTPS to HTTP Redirect |
| CVE-2026-79777 | 2.7 LOW | rclone before v1.75.0 Information Disclosure via RC API |
No comments yet