Medium severity4.7NVD Advisory· Published Aug 13, 2026· Updated Aug 31, 2026
CVE-2026-53800
CVE-2026-53800
Description
rsync before 3.5.0 contains a symlink race condition vulnerability in the --remove-source-files feature that allows attackers with symlink creation access to cause arbitrary file deletion. Attackers can atomically substitute a symlink for a source file between transfer completion and the unlink() call, causing rsync to delete the symlink target rather than the intended source file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
3- github.com/RsyncProject/rsync/security/advisories/GHSA-v3vw-pvpg-chwhnvdVendor Advisory
- www.vulncheck.com/advisories/rsync-symlink-race-condition-via-remove-source-filesnvdRelease NotesThird Party Advisory
- github.com/RsyncProject/rsync/releases/tag/v3.5.0nvdProductRelease Notes
News mentions
1- Rsync: 25 Vulnerabilities Disclosed Together, Affecting Versions Before 3.5.0Vypr Intelligence · Aug 13, 2026