Skip to content
Noroxi

rclone records

14 published records for vendor rclone.

All records

14 records
  • Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix

    CriticalCVSS 9.8No exploitEPSS 1%

    rclone · rcloneJun 24, 2026

  • rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass

    CriticalCVSS 9.8No exploitEPSS 1%

    rclone · rcloneSep 10, 2026

  • RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution

    CriticalCVSS 9.2Proof of conceptEPSS 5%

    rclone · rcloneApr 22, 2026

  • Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution

    CriticalCVSS 9.2Proof of conceptEPSS 3%

    rclone · rcloneApr 22, 2026

  • rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories

    HighCVSS 8.8No exploitEPSS 1%

    rclone · rcloneJul 14, 2026

  • rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote

    HighCVSS 8.8No exploitEPSS 0%

    rclone · rcloneJul 14, 2026

  • An issue was discovered in Rclone before 1.53.3.

    HighCVSS 7.5No exploitEPSS 1%

    rclone · rcloneNov 19, 2020

  • In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to trigger the transmiss

    HighCVSS 7.5No exploitEPSS 1%

    rclone · rcloneJun 27, 2018

  • rclone: FTP cross-session auth-proxy backend confusion

    HighCVSS 7.3No exploitEPSS 0%

    rclone · rcloneSep 10, 2026

  • rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination

    HighCVSS 7.1No exploitEPSS 0%

    rclone · rcloneSep 10, 2026

  • rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace

    MediumCVSS 6.3No exploitEPSS 0%

    rclone · rcloneSep 10, 2026

  • rclone local: crafted Range request against a translated symlink panics (DoS)

    MediumCVSS 5.3No exploitEPSS 1%

    rclone · rcloneSep 10, 2026

  • rclone: http backend forwards custom/auth headers to a different host on redirect

    MediumCVSS 5.3No exploitEPSS 0%

    rclone · rcloneSep 10, 2026

  • rclone archive extract allows S3 destination prefix escape via crafted archive paths

    MediumCVSS 5.0No exploitEPSS 0%

    rclone · rcloneJul 14, 2026