Command-Line Program Vulnerability in Rclone Affecting Remote SFTP Paths
CVE-2026-71312

8HIGH

Key Information:

Vendor

Rclone

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-71312?

Rclone, a command-line tool for syncing files and directories with cloud storage providers, has a vulnerability that affects versions prior to v1.75.0. The issue arises when remote SFTP paths are interpolated into PowerShell commands that do not properly escape certain Unicode characters used as single-quote delimiters. An attacker can manipulate filenames to terminate the intended path and append malicious PowerShell commands. This security flaw allows for remote code execution under the context of the victim's SSH account during server-side hashing operations. This vulnerability has been addressed in version v1.75.0.

Affected Version(s)

rclone < 1.75.0

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.