LOW 2.3 NVD
CVE-2026-93986
rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object n
rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names. Attackers can craft special names containing forward slashes and parent directory references to potentially write outside the destination root, though downstream protections in the local backend currently block actual file escape.
References
- https://github.com/rclone/rclone/security/advisories/GHSA-3vxh-3pcx-9m8q
- https://www.vulncheck.com/advisories/rclone-before-1.75.1-path-traversal-via-directory-lis
This low severity vulnerability with a CVSS score of 2.3 was published on 2026-09-19 via NVD.
vulnfeed aggregates 14147 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.