Description
rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names. Attackers can craft special names containing forward slashes and parent directory references to potentially write outside the destination root, though downstream protections in the local backend currently block actual file escape.
Published: 2026-09-19
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Local Path Traversal
Action: Assess Impact
AI Analysis

Impact

The vulnerability occurs when rclone, before version 1.75.1, does not validate names in server or third‑party listing responses against the target directory. Attackers can create specially crafted object names that include forward slashes and parent‑directory references, potentially allowing writes outside the intended destination root and giving the ability to overwrite arbitrary local files. The weakness is a classic Path Traversal (CWE‑22). Current local backend checks block actual file escape, but the flaw still poses a risk if downstream protections are bypassed or internal logic changes.

Affected Systems

All installations of rclone rclone before version 1.75.1, including self‑hosted and managed deployments, are affected.

Risk and Exploitability

The CVSS score of 2.3 indicates a low severity, and the EPSS score is not available, with the vulnerability not listed in the CISA KEV catalog. The attack vector is likely remote or local via malicious directory listings; an attacker would need to influence the remote storage service or a third‑party provider to deliver crafted object names. Existing local backend controls prevent actual escape in the current implementation, but the flaw remains exploitable if those controls are circumvented.

Generated by OpenCVE AI on September 19, 2026 at 23:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade rclone to version 1.75.1 or later to remove the path traversal flaw.
  • Verify that any third‑party storage providers or remote services handling object names perform proper input validation or enforce a whitelist of permissible characters.
  • Configure or review local backend settings to enforce strict destination path validations and consider disabling the use of third‑party metadata that may contain malicious path sequences.

Generated by OpenCVE AI on September 19, 2026 at 23:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Description rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names. Attackers can craft special names containing forward slashes and parent directory references to potentially write outside the destination root, though downstream protections in the local backend currently block actual file escape.
Title rclone before 1.75.1 Path Traversal via Directory Listing Names
First Time appeared Rclone
Rclone rclone
Weaknesses CWE-22
CPEs cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:*
Vendors & Products Rclone
Rclone rclone
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T20:46:58.617Z

Reserved: 2026-09-19T10:55:49.093Z

Link: CVE-2026-93986

cve-icon Vulnrichment

Updated: 2026-09-21T16:22:59.409Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-19T12:16:42.027

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-93986

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-19T11:53:37Z

Links: CVE-2026-93986 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:00:10Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')