rclone 是一个用于在不同云存储提供商之间同步文件和目录的命令行程序。在版本 1.72.0 到 1.75.1 期间,归档 ZIP 后端的 方法(位于 )会接受来自不可信中央目录的 值,并在暴露经过清理的条目名称时,未能确保这些名称仍然位于归档命名空间内部。例如,形如 的条目可能在 之后依然保留,并成为 的值,而 和 会将其作为目标相对路径使用,从而导致在不自行约束路径的后端上, 或 可能会将文件写入所选目标目录之外的位置。此外,非空根目录的检查使用了 且未加路径边界判断,因此根目录为 时可能会错误地包含其同级目
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88018 | 9.8 CRITICAL | rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signatu |
| CVE-2026-88044 | 9.1 CRITICAL | rclone: RC per-server auth-proxy bypass |
| CVE-2026-88045 | 7.5 HIGH | rclone: S3 multipart declared-length memory exhaustion |
| CVE-2026-88017 | 7.3 HIGH | rclone: FTP cross-session auth-proxy backend confusion |
| CVE-2026-88016 | 7.1 HIGH | rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclo |
| CVE-2026-88015 | 5.3 MEDIUM | rclone local: crafted Range request against a translated symlink panics (DoS) |
| CVE-2026-88046 | 5.3 MEDIUM | rclone: source object names can escape the configured root on upload |
| CVE-2026-88013 | 3.7 LOW | rclone: http backend forwards custom/auth headers to a different host on redirect |
No comments yet