rclone 是一个用于在不同云存储提供商之间同步文件和目录的命令行工具。在 1.75.1 之前的版本中,当 backend/local 以 参数运行时,源端的一个 对象可以在目标端创建一个符号链接(symlink),并且后续的目录元数据会通过该路径应用。由于 、 和 在 时生效,导致 、 、 以及 birth-time(创建时间)的处理会绕过 的约束,并跟随该符号链接。因此,能够控制源端内容的攻击者可以在目标端之外的文件或目录上设置特定的所有权、权限、修改时间或创建时间。其中, 和 需要启用 参数,而修改时间则通
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88018 | 9.8 CRITICAL | rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signatu |
| CVE-2026-88044 | 9.1 CRITICAL | rclone: RC per-server auth-proxy bypass |
| CVE-2026-88045 | 7.5 HIGH | rclone: S3 multipart declared-length memory exhaustion |
| CVE-2026-88017 | 7.3 HIGH | rclone: FTP cross-session auth-proxy backend confusion |
| CVE-2026-88014 | 6.3 MEDIUM | rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive esca |
| CVE-2026-88015 | 5.3 MEDIUM | rclone local: crafted Range request against a translated symlink panics (DoS) |
| CVE-2026-88046 | 5.3 MEDIUM | rclone: source object names can escape the configured root on upload |
| CVE-2026-88013 | 3.7 LOW | rclone: http backend forwards custom/auth headers to a different host on redirect |
No comments yet