Impact
The vulnerability arises when rclone processes source object names that contain parent‑directory segments ("..") before sanitizing them. It allows an upload or sync operation to write data outside the intended bucket or path. Based on the description, the primary impact is unauthorized data access or modification, potentially leaking or overwriting files in other shared buckets or directories reachable by the same credentials.
Affected Systems
This issue affects rclone installations prior to version 1.75.1 when used with any cloud backends that concatenate the configured root and the remote path before neutralizing dot segments. A flat‑keyspace source store containing raw ".." entries makes b2, swift, qingstor, oracleobjectstorage, internetarchive, smb, storj, sftp, webdav, ftp, filelu, shade, and sia destinations vulnerable. The vulnerability is present in any rclone installation running 1.75.0 or earlier; the fix is in v1.75.1.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread exploitation has not been reported. The likely attack vector is an authenticated rclone user who performs a copy or upload command using a source store that contains raw ".." segments. Based on the description, it is inferred that such an operation causes the destination backend to write data outside the configured root, potentially reaching other buckets or paths within the user's authority. This could allow unauthorized data access or modification.
OpenCVE Enrichment
Github GHSA