CRITICAL 9.2 NVD

CVE-2026-53790

rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious in

rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and remote-shell command newline injection. Attackers can inject shell metacharacters or newline characters into unsanitized user-supplied values such as hostnames and hostspecs to execute arbitrary commands under the privileges of the rsync process or the invoking user.

References

Published: 2026-08-13 · Source: NVD · Feed updated: 2026-08-13
This critical severity vulnerability with a CVSS score of 9.2 was published on 2026-08-13 via NVD.

Risk Timeline

CVE Disclosed2026-08-13 · -1 days ago

Remediation Resources

vulnfeed aggregates 10617 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.