Description
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone core does not reject parent-directory segments in source Object.Remote() values before fs/list, fs/walk, fs/sync, and fs/operations pass those values to destination backends. A flat-keyspace source object store populated with native non-rclone tooling can contain a raw .. key segment, and affected b2, swift, qingstor, oracleobjectstorage, internetarchive, smb, storj, sftp, webdav, ftp, filelu, shade, and sia destinations use path.Join(root, remote) before EncodeDot can neutralize the segment. A copy or upload can therefore escape the configured root into another bucket, share, or path reachable by the victim credential, with sftp and smb potentially reaching other filesystem or share locations under the same login authority. This issue is fixed in version 1.75.1.
Published: 2026-09-10
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access via Path Traversal
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises when rclone processes source object names that contain parent‑directory segments ("..") before sanitizing them. It allows an upload or sync operation to write data outside the intended bucket or path. Based on the description, the primary impact is unauthorized data access or modification, potentially leaking or overwriting files in other shared buckets or directories reachable by the same credentials.

Affected Systems

This issue affects rclone installations prior to version 1.75.1 when used with any cloud backends that concatenate the configured root and the remote path before neutralizing dot segments. A flat‑keyspace source store containing raw ".." entries makes b2, swift, qingstor, oracleobjectstorage, internetarchive, smb, storj, sftp, webdav, ftp, filelu, shade, and sia destinations vulnerable. The vulnerability is present in any rclone installation running 1.75.0 or earlier; the fix is in v1.75.1.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, and the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread exploitation has not been reported. The likely attack vector is an authenticated rclone user who performs a copy or upload command using a source store that contains raw ".." segments. Based on the description, it is inferred that such an operation causes the destination backend to write data outside the configured root, potentially reaching other buckets or paths within the user's authority. This could allow unauthorized data access or modification.

Generated by OpenCVE AI on September 11, 2026 at 01:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to rclone v1.75.1 or higher to receive the patch that rejects '..' segments in source object names before processing.
  • Sanitize source object names to remove parent‑directory segments that could cause traversal.
  • Audit upload scripts and automation tools for inadvertent use of untrusted content and verify that the configured root path is enforced by the updated rclone.

Generated by OpenCVE AI on September 11, 2026 at 01:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-38xv-hf3p-h7mq rclone: source object names can escape the configured root on upload
History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 11 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Rclone
Rclone rclone
Vendors & Products Rclone
Rclone rclone

Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone core does not reject parent-directory segments in source Object.Remote() values before fs/list, fs/walk, fs/sync, and fs/operations pass those values to destination backends. A flat-keyspace source object store populated with native non-rclone tooling can contain a raw .. key segment, and affected b2, swift, qingstor, oracleobjectstorage, internetarchive, smb, storj, sftp, webdav, ftp, filelu, shade, and sia destinations use path.Join(root, remote) before EncodeDot can neutralize the segment. A copy or upload can therefore escape the configured root into another bucket, share, or path reachable by the victim credential, with sftp and smb potentially reaching other filesystem or share locations under the same login authority. This issue is fixed in version 1.75.1.
Title rclone: source object names can escape the configured root on upload
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T14:47:32.868Z

Reserved: 2026-09-09T21:22:45.433Z

Link: CVE-2026-88046

cve-icon Vulnrichment

Updated: 2026-09-15T14:47:27.951Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T17:17:08.677

Modified: 2026-09-15T15:17:24.440

Link: CVE-2026-88046

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-10T16:14:49Z

Links: CVE-2026-88046 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T08:00:13Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')