VYPR

Rclone

by Rclone

Source repositories

CVEs (34)

  • CVE-2024-52522MedNov 15, 2024
    risk 0.28cvss —epss 0.00

    Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions…

  • CVE-2026-88046MedSep 10, 2026
    risk 0.27cvss 5.3epss 0.00

    rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone core does not reject parent-directory segments in source Object.Remote() values before fs/list, fs/walk, fs/sync, and fs/operations pass those…

  • CVE-2026-88015MedSep 10, 2026
    risk 0.27cvss 5.3epss 0.00

    rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects, and fs.RangeOption.Decode can pass an unchecked positive Range…

  • CVE-2026-79780MedAug 25, 2026
    risk 0.27cvss 5.3epss 0.00

    rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, allowing credentials to be preserved across scheme or host changes. Attackers observing network traffic from a trusted endpoint can capture reusable IBM IAM…

  • CVE-2026-79779MedAug 25, 2026
    risk 0.27cvss 5.3epss 0.00

    rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects. An on-path attacker observing the plaintext hop can capture and…

  • CVE-2026-79778MedAug 25, 2026
    risk 0.27cvss 5.3epss 0.00

    rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler that dereferences a nil response before checking for transport errors. A malicious or compromised configured endpoint can reset connections during TUS uploads to trigger a panic…

  • CVE-2026-79776MedAug 25, 2026
    risk 0.27cvss 5.3epss 0.00

    rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication rule in the main handler. Attackers can access the /debug/pprof/cmdline endpoint unauthenticated to retrieve the full process argv including backend credentials.

  • CVE-2026-59732MedJul 14, 2026
    risk 0.26cvss 5.0epss 0.00

    Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone archive extract can write extracted files outside the user-selected destination prefix when extracting a crafted archive containing parent path…

  • CVE-2026-88013LowSep 10, 2026
    risk 0.17cvss 3.7epss 0.00

    rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.49.0 until 1.75.1, the HTTP backend attaches headers configured through --http-headers or headers= to requests in backend/http/http.go, while its fshttp.NewClient…

  • CVE-2026-79783LowAug 25, 2026
    risk 0.16cvss 3.6epss 0.00

    rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files. When copying with metadata preservation from an untrusted remote, attackers can…

  • CVE-2026-93987LowSep 19, 2026
    risk 0.15cvss 3.4epss 0.00

    rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin. newVolume() in cmd/serve/docker/volume.go computes a volume's mountpoint as filepath.Join(drv.root, name) from the attacker-supplied `name` field of a Docker…

  • CVE-2026-93986LowSep 19, 2026
    risk 0.13cvss 3.1epss 0.00

    rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names. Attackers can craft special names containing forward slashes and parent directory references to potentially write…

  • CVE-2026-79782LowAug 25, 2026
    risk 0.13cvss 3.1epss 0.00

    rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can intercept plaintext HTTP traffic to capture AWS STS session tokens sent in request headers.

  • CVE-2026-79777LowAug 25, 2026
    risk 0.11cvss 2.7epss 0.00

    rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses.

Page 2 of 2