Description
rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin. newVolume() in cmd/serve/docker/volume.go computes a volume's mountpoint as filepath.Join(drv.root, name) from the attacker-supplied `name` field of a Docker VolumeDriver.Create request without verifying that the result stays within drv.root (default /var/lib/docker-volumes/rclone), and checkMountpoint() then creates that directory with file.MkdirAll before mounting. A volume name containing enough `..` components (e.g. "../../../../../../etc") therefore resolves outside the base directory, allowing anyone able to submit a VolumeDriver.Create request to the plugin socket — normally the Docker daemon, or a workload that can request named volumes in a multi-tenant orchestration setup — to make the privileged rclone plugin process create a directory and mount a remote filesystem specified in the same request at an arbitrary host path, shadowing or disrupting system directories. The advisory notes Volume.restoreState() had the same missing validation when reloading persisted volume state. Fixed in 1.75.1.
Published: 2026-09-19
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

The rclone serve docker volume plugin in versions 1.56.0 through 1.75.0 contains a path traversal flaw (CWE‑73) that fails to validate the volume name supplied in a Docker VolumeDriver.Create request. When an attacker supplies a volume name containing enough ".." components, the plugin concatenates it with its root directory without bounds checking, allowing directories to be created outside the intended base path. This enables the privileged rclone process to mount a remote filesystem at an arbitrary host location, potentially overwriting or shadowing system directories.

Affected Systems

rclone versions 1.56.0 through 1.75.0, inclusive, through the serve docker volume plugin. The vulnerability also existed in the Volume.restoreState functionality that reloaded persisted volumes. Affected installations run the rclone plugin with root or container privileges and expose the Docker volume driver gRPC endpoint on localhost or a network socket. Updating to rclone 1.75.1 or later removes the missing validation logic.

Risk and Exploitability

CVSS base score 4.6 indicates moderate impact. EPSS score not available, so no current estimate of exploitation frequency. The vulnerability is not listed in the CISA KEV catalog. Attackers need the ability to invoke the Docker volume driver Create interface; in multi‑tenant orchestrations or mis‑configured Docker daemons this is a realistic privilege. Exploitation is straightforward once the socket is reachable, as the plugin will perform the path traversal and mount command with its own privileges.

Generated by OpenCVE AI on September 19, 2026 at 23:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade rclone to version 1.75.1 or later to fix the vulnerability.
  • Restrict access to the Docker volume driver socket to trusted users or services only, preventing unauthenticated processes from invoking Create.
  • Review orchestration configurations to ensure that containers or workloads that can request named volumes are confined to namespaces that do not expose the plugin socket to untrusted tenants.

Generated by OpenCVE AI on September 19, 2026 at 23:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Description rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin. newVolume() in cmd/serve/docker/volume.go computes a volume's mountpoint as filepath.Join(drv.root, name) from the attacker-supplied `name` field of a Docker VolumeDriver.Create request without verifying that the result stays within drv.root (default /var/lib/docker-volumes/rclone), and checkMountpoint() then creates that directory with file.MkdirAll before mounting. A volume name containing enough `..` components (e.g. "../../../../../../etc") therefore resolves outside the base directory, allowing anyone able to submit a VolumeDriver.Create request to the plugin socket — normally the Docker daemon, or a workload that can request named volumes in a multi-tenant orchestration setup — to make the privileged rclone plugin process create a directory and mount a remote filesystem specified in the same request at an arbitrary host path, shadowing or disrupting system directories. The advisory notes Volume.restoreState() had the same missing validation when reloading persisted volume state. Fixed in 1.75.1.
Title rclone serve docker Path Traversal via Volume Name
First Time appeared Rclone
Rclone rclone
Weaknesses CWE-73
CPEs cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:*
Vendors & Products Rclone
Rclone rclone
References
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 4.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T18:29:11.792Z

Reserved: 2026-09-19T10:55:49.093Z

Link: CVE-2026-93987

cve-icon Vulnrichment

Updated: 2026-09-21T18:29:05.829Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-19T12:16:42.187

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-93987

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:45:16Z

Weaknesses
  • CWE-73

    External Control of File Name or Path