Command-Line Program Vulnerability in Rclone Affecting Remote SFTP Paths
CVE-2026-71312
8HIGH
What is CVE-2026-71312?
Rclone, a command-line tool for syncing files and directories with cloud storage providers, has a vulnerability that affects versions prior to v1.75.0. The issue arises when remote SFTP paths are interpolated into PowerShell commands that do not properly escape certain Unicode characters used as single-quote delimiters. An attacker can manipulate filenames to terminate the intended path and append malicious PowerShell commands. This security flaw allows for remote code execution under the context of the victim's SSH account during server-side hashing operations. This vulnerability has been addressed in version v1.75.0.
Affected Version(s)
rclone < 1.75.0
