Impact
The rclone serve docker volume plugin in versions 1.56.0 through 1.75.0 contains a path traversal flaw (CWE‑73) that fails to validate the volume name supplied in a Docker VolumeDriver.Create request. When an attacker supplies a volume name containing enough ".." components, the plugin concatenates it with its root directory without bounds checking, allowing directories to be created outside the intended base path. This enables the privileged rclone process to mount a remote filesystem at an arbitrary host location, potentially overwriting or shadowing system directories.
Affected Systems
rclone versions 1.56.0 through 1.75.0, inclusive, through the serve docker volume plugin. The vulnerability also existed in the Volume.restoreState functionality that reloaded persisted volumes. Affected installations run the rclone plugin with root or container privileges and expose the Docker volume driver gRPC endpoint on localhost or a network socket. Updating to rclone 1.75.1 or later removes the missing validation logic.
Risk and Exploitability
CVSS base score 4.6 indicates moderate impact. EPSS score not available, so no current estimate of exploitation frequency. The vulnerability is not listed in the CISA KEV catalog. Attackers need the ability to invoke the Docker volume driver Create interface; in multi‑tenant orchestrations or mis‑configured Docker daemons this is a realistic privilege. Exploitation is straightforward once the socket is reachable, as the plugin will perform the path traversal and mount command with its own privileges.
OpenCVE Enrichment