File Overwrite Vulnerability in Rclone Command-Line Tool
CVE-2026-71313
6.9MEDIUM
What is CVE-2026-71313?
The Rclone command-line tool has a file overwrite vulnerability present in versions 1.51.0 to 1.75.0, caused by inadequate filename encoding handling within the local backend. This allows attackers to manipulate filenames in such a way that files can be created or overwritten in unintended directories outside of the designated local root, potentially compromising sensitive data. Users are advised to upgrade to version 1.75.0, which addresses this security flaw.
Affected Version(s)
rclone >= 1.51.0, < 1.75.0
