MEDIUM 6.4 GitHub
CVE-2026-71311
rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines
## 1. Summary
A valid but nondefault FTP filename encoding can restore raw CR/LF immediately before an attacker-controlled path is interpolated into the line-oriented FTP control channel. The dependency does not reject CR or LF in command arguments, so a filename can inject an independent authenticated command. A real test server observed the injected `DELE` command.
The default FTP encoding and the configuration-wizard examples include `Ctl` and are not vulnerable to the demonstrated filename
Affected Products
- go/github.com/rclone/rclone < 1.75.0
References
- https://github.com/advisories/GHSA-8c48-q9wj-3w37
- https://github.com/rclone/rclone/security/advisories/GHSA-8c48-q9wj-3w37
- https://github.com/rclone/rclone/commit/1df2b70753286c1dfe8366078cbedfdf7f96472c
- https://github.com/rclone/rclone/releases/tag/v1.75.0
This medium severity vulnerability with a CVSS score of 6.4 was published on 2026-08-05 via GitHub. Affected: go/github.com/rclone/rclone < 1.75.0.
vulnfeed aggregates 9344 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.