CVE-2026-93986 - rclone before 1.75.1 Path Traversal via Directory Listing Names
CVE ID :CVE-2026-93986
Published : Sept. 19, 2026, 12:16 p.m. | 52 minutes ago
Description :rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names. Attackers can craft special names containing forward slashes and parent directory references to potentially write outside the destination root, though downstream protections in the local backend currently block actual file escape.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 19, 2026, 12:16 p.m. | 52 minutes ago
Description :rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names. Attackers can craft special names containing forward slashes and parent directory references to potentially write outside the destination root, though downstream protections in the local backend currently block actual file escape.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...