Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

rclone — Vulnerabilities & Security Advisories 21

Browse all 21 CVE security advisories affecting rclone. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Rclone is a command-line utility for synchronizing files to and from various cloud storage providers, serving as a core tool for data migration and backup operations. Historically, it has been susceptible to remote code execution vulnerabilities through improper input validation and insecure default configurations, along with privilege escalation flaws due to insufficient permission checks. While no major security incidents have been widely documented, the three recorded CVEs highlight risks in authentication mechanisms and insecure temporary file handling. The tool's cross-platform nature and extensive provider support increase its attack surface, particularly when used with privileged credentials or in automated deployment scenarios where misconfigurations could lead to data compromise.

Top products by rclone: rclone
CVE ID Title CVSS Severity Published
CVE-2026-79783 rclone before 1.74.4 Privilege Escalation via setuid Metadata — rclone CWE-732 3.6 Low 2026-08-25
CVE-2026-79782 rclone before 1.74.4 Security Token Disclosure via HTTPS to HTTP Redirect — rclone CWE-319 3.1 Low 2026-08-25
CVE-2026-79781 rclone serve s3 Path Traversal via dot-dot object keys — rclone CWE-22 6.5 Medium 2026-08-25
CVE-2026-79780 rclone before v1.75.0 Credential Exposure via S3 Redirect — rclone CWE-200 5.3 Medium 2026-08-25
CVE-2026-79779 rclone before v1.75.0 WebDAV Credential Exposure via HTTPS-to-HTTP Redirect — rclone CWE-319 5.3 Medium 2026-08-25
CVE-2026-79778 rclone before v1.75.0 Denial of Service via TUS nil-response panic — rclone CWE-248 5.3 Medium 2026-08-25
CVE-2026-79777 rclone before v1.75.0 Information Disclosure via RC API — rclone CWE-209 2.7 Low 2026-08-25
CVE-2026-79776 rclone before 1.75.0 Authentication Bypass via pprof — rclone CWE-200 5.3 Medium 2026-08-25
CVE-2026-79775 rclone Archive Backend SquashFS Parser Denial of Service — rclone CWE-129 6.5 Medium 2026-08-25
CVE-2026-71313 rclone: Local Encoding Path Traversal — rclone CWE-22 6.9 Medium 2026-08-05
CVE-2026-71312 rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution — rclone CWE-78 8.0 High 2026-08-05
CVE-2026-71311 rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines — rclone CWE-93 6.4 Medium 2026-08-05
CVE-2026-71310 rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory — rclone CWE-400 5.9 Medium 2026-08-05
CVE-2026-71309 rclone: Incomplete path validation allows backend root escape in serve restic — rclone CWE-22 8.6 High 2026-08-05
CVE-2026-59733 rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories — rclone CWE-22 8.8 High 2026-07-14
CVE-2026-54572 rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote — rclone CWE-59 7.5 High 2026-07-14
CVE-2026-59732 rclone archive extract allows S3 destination prefix escape via crafted archive paths — rclone CWE-22 5.0 Medium 2026-07-14
CVE-2026-49980 Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix — rclone CWE-306 9.8 Critical 2026-06-24
CVE-2026-41179 RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution — rclone CWE-78 9.8 - 2026-04-23
CVE-2026-41176 Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution — rclone CWE-306 9.1 - 2026-04-22
CVE-2024-52522 Rclone Improper Permission and Ownership Handling on Symlink Targets with --links and --metadata — rclone CWE-59 8.2 - 2024-11-15

This page lists every published CVE security advisory associated with rclone. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.