Symlink Vulnerability in Rclone Command-Line Tool
CVE-2026-88016
7.1HIGH
What is CVE-2026-88016?
Rclone, a command-line tool designed for syncing files and directories with various cloud storage providers, has a vulnerability related to symlink handling in versions before 1.75.1. When utilizing the --links option, an attacker can manipulate a .rclonelink object to create a symlink in the destination. This allows the attacker to manipulate file or directory metadata, including ownership and permissions, thereby bypassing security measures like os.Root confinement. The exploit permits unauthorized control over files outside the intended destination, making it critical for users to upgrade to version 1.75.1 or above for protection against this vulnerability.
Affected Version(s)
rclone < 1.75.1
