Path Traversal Vulnerability in Rclone S3 Service
CVE-2026-79781
6.9MEDIUM
What is CVE-2026-79781?
The rclone serve s3 feature prior to version 1.74.4 is susceptible to a path traversal vulnerability. This flaw enables an attacker to manipulate S3 object keys using dot-dot segments, such as '../root-secret.txt', to escape the intended bucket namespace. Consequently, this allows unauthorized access to and manipulation of sensitive files located in the root directory of the server. This exploitation poses significant risks to data integrity and confidentiality in the affected environments.
Affected Version(s)
rclone 0 < 1.74.4
rclone 1.74.4
