Impact
The vulnerability occurs when rclone, before version 1.75.1, does not validate names in server or third‑party listing responses against the target directory. Attackers can create specially crafted object names that include forward slashes and parent‑directory references, potentially allowing writes outside the intended destination root and giving the ability to overwrite arbitrary local files. The weakness is a classic Path Traversal (CWE‑22). Current local backend checks block actual file escape, but the flaw still poses a risk if downstream protections are bypassed or internal logic changes.
Affected Systems
All installations of rclone rclone before version 1.75.1, including self‑hosted and managed deployments, are affected.
Risk and Exploitability
The CVSS score of 2.3 indicates a low severity, and the EPSS score is not available, with the vulnerability not listed in the CISA KEV catalog. The attack vector is likely remote or local via malicious directory listings; an attacker would need to influence the remote storage service or a third‑party provider to deliver crafted object names. Existing local backend controls prevent actual escape in the current implementation, but the flaw remains exploitable if those controls are circumvented.
OpenCVE Enrichment