HIGH GitHub
CVE-2026-71309
rclone: Incomplete path validation allows backend root escape in serve restic
## Summary
`rclone serve restic` does not correctly reject URL paths beginning with `../`. On affected backends, an attacker who can access the REST endpoint can read, create, overwrite, or delete objects outside the path configured by the operator.
The issue affects `rclone v1.40` through `rclone v1.74.4`. The proof of concept and backend matrix were validated with the official Linux AMD64 binary for `v1.74.4`, and the latest `master` commit reviewed at the time (`2217d38`) contained the same
Affected Products
- go/github.com/rclone/rclone >= 1.40.0, < 1.75.0
References
- https://github.com/advisories/GHSA-45pq-889g-fcgh
- https://github.com/rclone/rclone/security/advisories/GHSA-45pq-889g-fcgh
- https://github.com/rclone/rclone/commit/cc5a189f00efe68ed0ddb32d3237b42549a9f264
- https://github.com/rclone/rclone/releases/tag/v1.75.0
This high severity vulnerability was published on 2026-08-05 via GitHub. Affected: go/github.com/rclone/rclone >= 1.40.0, < 1.75.0.
vulnfeed aggregates 9344 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.