Arbitrary File Overwrite in rclone from 1.72.0 to 1.75.1
CVE-2026-88014
6.3MEDIUM
What is CVE-2026-88014?
The rclone command-line program, used for syncing files with various cloud storage providers, has a directory traversal vulnerability between versions 1.72.0 and 1.75.1. Specifically, the archive ZIP backend method incorrectly processes file names from untrusted central directories, allowing potential writes outside designated directories. This flaw arises when path cleaning operations fail to enforce proper boundaries, which can lead to unauthorized access to file systems. Users are strongly advised to upgrade to version 1.75.1 or later to mitigate this risk.
Affected Version(s)
rclone >= 1.72.0, < 1.75.1
