HIGH 8.0 GitHub
CVE-2026-71312
rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution
## 1. Summary
rclone interpolates remote SFTP paths into PowerShell hash commands. Its quoting helper escapes only ASCII apostrophe, although PowerShell accepts four Unicode smart quotes as single-quote delimiters. An attacker-controlled filename can therefore terminate the intended path literal and append PowerShell statements executed as the victim's SSH account.
## 2. Affected Assets & Attack Surface
- Audited commit: `a0c09f1381ae93e2a9a33c529d170186c61ad058`
- Backend: `backend/sftp`
- R
Affected Products
- go/github.com/rclone/rclone <= 1.74.4
References
- https://github.com/advisories/GHSA-2m8m-jhrm-w6j2
- https://github.com/rclone/rclone/security/advisories/GHSA-2m8m-jhrm-w6j2
- https://github.com/rclone/rclone/commit/e122fba1a57641b63a580aa26c026903a84e2e88
- https://github.com/rclone/rclone/releases/tag/v1.75.0
This high severity vulnerability with a CVSS score of 8.0 was published on 2026-08-05 via GitHub. Affected: go/github.com/rclone/rclone <= 1.74.4.
vulnfeed aggregates 9344 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.