CVE-2026-54572
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks as .rclonelink text objects and recreates them on a local destination without validating the target, allowing an attacker-controlled remote to plant an escaping symlink and cause a following object write to land outside the destination with attacker-chosen contents. This issue is fixed in version 1.74.4.
Schwachstellenklasse
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks as .rclonelink text objects and recreates them on a local destination without validating the target, allowing an attacker-controlled remote to plant an escaping symlink and cause a following object write to land outside the destination with attacker-chosen contents. This issue is fixed in version 1.74.4.
Betroffene Produkte
- rclone rclone
Quellen
- https://github.com/rclone/rclone/commit/1154afebee986180b489084d38e2a0c578751498
- https://github.com/rclone/rclone/commit/874a804f5289517defdd7de68b2a374837080265
- https://github.com/rclone/rclone/releases/tag/v1.74.4
- https://github.com/rclone/rclone/security/advisories/GHSA-cf44-9pgv-m4xc
- https://github.com/rclone/rclone/security/advisories/GHSA-cf44-9pgv-m4xc
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.