LOW 2.3 NVD

CVE-2026-93986

rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object n

rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names. Attackers can craft special names containing forward slashes and parent directory references to potentially write outside the destination root, though downstream protections in the local backend currently block actual file escape.

References

Published: 2026-09-19 · Source: NVD · Feed updated: 2026-09-19
This low severity vulnerability with a CVSS score of 2.3 was published on 2026-09-19 via NVD.
vulnfeed aggregates 14147 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.