Path Traversal Vulnerability in Rclone Command-Line Tool
CVE-2026-71309

8.6HIGH

Key Information:

Vendor

Rclone

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-71309?

Rclone, a command-line tool for syncing files and directories across various cloud storage providers, is affected by a path traversal vulnerability. In versions 1.40.0 to 1.75.0, the 'rclone serve restic' command does not properly validate URL paths that begin with '../'. This flaw allows an attacker accessing the REST endpoint to read, create, modify, or delete files beyond the designated directory, posing significant security risks. This issue has been resolved in version 1.75.0. For further details, refer to the GitHub advisory.

Affected Version(s)

rclone >= 1.40.0, < 1.75.0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.