File Overwrite Vulnerability in Rclone Command-Line Tool
CVE-2026-71313

6.9MEDIUM

Key Information:

Vendor

Rclone

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-71313?

The Rclone command-line tool has a file overwrite vulnerability present in versions 1.51.0 to 1.75.0, caused by inadequate filename encoding handling within the local backend. This allows attackers to manipulate filenames in such a way that files can be created or overwritten in unintended directories outside of the designated local root, potentially compromising sensitive data. Users are advised to upgrade to version 1.75.0, which addresses this security flaw.

Affected Version(s)

rclone >= 1.51.0, < 1.75.0

References

CVSS V3.1

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.