Path Traversal Vulnerability in Rclone Software by Rclone, Inc.
CVE-2026-93986
2.3LOW
What is CVE-2026-93986?
The vulnerability in Rclone versions prior to 1.75.1 arises from inadequate confinement of names generated from server and third-party directory listings. This oversight allows attackers to exploit crafted object names that include path traversal sequences such as forward slashes and parent directory references. Although local backend protections currently mitigate the risk of unauthorized file writing outside the intended directory, the flaw still exposes systems to potential exploitation and emphasizes the need for an immediate update.
Affected Version(s)
rclone 0 < 1.75.1
rclone 1.75.1
