Impact
rclone versions before 1.75.1 have a flaw whereby a source .rclonelink object can plant a symbolic link in the destination during a sync that uses the --links option. When directory metadata is later applied through that planted link, the program writes ownership, permission, and timestamp data to files or directories outside the intended destination path. This bypasses normal root confinement protection in the code and allows an attacker who can supply source data to set arbitrary user IDs, group IDs, permissions, or timestamps on chosen files outside the target directory.
Affected Systems
The vulnerable product, rclone, using a version earlier than 1.75.1 and employing the --links flag during a sync is affected. Only these pre‑1.75.1 builds are impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires local access: the attacker must control the source contents and run rclone with --links (and optionally --metadata) on a system where the destination is writable. Although no network exposure is required, the flaw can be leveraged for privilege escalation by changing ownership or permissions of critical files outside the intended sync destination.
OpenCVE Enrichment
Github GHSA