Path Traversal Vulnerability in Rclone Docker Volume Plugin by Rclone
CVE-2026-93987

4.6MEDIUM

Key Information:

Vendor

Rclone

Status
Vendor
CVE Published:
19 September 2026

What is CVE-2026-93987?

The rclone versions 1.56.0 through 1.75.0 are susceptible to a path traversal vulnerability within the 'rclone serve docker' volume plugin. This vulnerability arises from the improper validation of an attacker-controlled 'name' field during the Docker VolumeDriver.Create request. As a result, the plugin can resolve mountpoint paths outside the intended directory structure, allowing unauthorized users to create directories and mount remote filesystems at arbitrary locations on the host system. This misconfiguration can lead to potential shadowing or disruption of critical system directories. The issue has been addressed in version 1.75.1.

Affected Version(s)

rclone 1.56.0 < 1.75.1

rclone 1.75.1

References

CVSS V4

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

iaohkut
ncw
.