Impact
rclone is a command‑line file‑synchronization tool that allows custom HTTP headers to be configured via the --http-headers option. Between versions 1.49.0 and 1.75.1 the HTTP backend attaches these headers to all outbound requests, and the HTTP client follows redirects without a tailored CheckRedirect policy. When a configured remote issues a redirect to a different host, the client automatically resends the configured headers—including secrets such as X-Api-Key, Authorization, or Cookie—to the target host. A same‑host HTTPS‑to‑HTTP redirect can also expose these credentials in clear text over the connection. The normal operations of rclone—listing, stat, download, mount, and serve—trigger this header forwarding during routine use, potentially leaking sensitive authentication data to an attacker who controls or observes the redirect destination.
Affected Systems
The vulnerability is present in rclone versions 1.49.0 through 1.75.0, a command‑line file‑synchronization tool that supports many cloud storage providers. Any installation of rclone within this range that configures custom HTTP headers or interacts with remote endpoints that may issue redirects is affected. The issue is resolved in rclone 1.75.1 and later.
Risk and Exploitability
The vulnerability has a CVSS score of 3.7, indicating low severity, and an EPSS score of less than 1 %, implying a very low exploitation probability. It is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers could exploit the redirect behavior to force rclone to forward sensitive headers to a malicious or compromised host. Although the required conditions are relatively common—using custom headers with a redirect—the likelihood of successful exploitation remains low, and the impact is primarily the accidental exposure of credentials or session tokens during normal use.
OpenCVE Enrichment
Github GHSA