Path Traversal Vulnerability in Rclone Docker Volume Plugin by Rclone
CVE-2026-93987
4.6MEDIUM
What is CVE-2026-93987?
The rclone versions 1.56.0 through 1.75.0 are susceptible to a path traversal vulnerability within the 'rclone serve docker' volume plugin. This vulnerability arises from the improper validation of an attacker-controlled 'name' field during the Docker VolumeDriver.Create request. As a result, the plugin can resolve mountpoint paths outside the intended directory structure, allowing unauthorized users to create directories and mount remote filesystems at arbitrary locations on the host system. This misconfiguration can lead to potential shadowing or disruption of critical system directories. The issue has been addressed in version 1.75.1.
Affected Version(s)
rclone 1.56.0 < 1.75.1
rclone 1.75.1
