FTP Command Injection Vulnerability in Rclone by Rclone
CVE-2026-71311

6.4MEDIUM

Key Information:

Vendor

Rclone

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-71311?

Rclone, a widely used command-line tool for syncing files with various cloud storage providers, had a significant vulnerability found in versions prior to 1.75.0. This vulnerability arose from improper handling of FTP filename encodings, which permitted an attacker to inject arbitrary FTP commands during file synchronization operations. By manipulating the control channel commands, an attacker could exploit the issue, affecting the integrity and confidentiality of the data being processed. This vulnerability was addressed and resolved in Rclone version 1.75.0, reinforcing the security framework around file transfer operations.

Affected Version(s)

rclone < 1.75.0

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.