Path Traversal Vulnerability in Rclone Command-Line Tool
CVE-2026-71309
8.6HIGH
What is CVE-2026-71309?
Rclone, a command-line tool for syncing files and directories across various cloud storage providers, is affected by a path traversal vulnerability. In versions 1.40.0 to 1.75.0, the 'rclone serve restic' command does not properly validate URL paths that begin with '../'. This flaw allows an attacker accessing the REST endpoint to read, create, modify, or delete files beyond the designated directory, posing significant security risks. This issue has been resolved in version 1.75.0. For further details, refer to the GitHub advisory.
Affected Version(s)
rclone >= 1.40.0, < 1.75.0
