CVEs we hold for Rclone
Records whose assigning authority named Rclone as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-88018rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypassrclone
CVE-2026-88016rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the…rclone
CVE-2026-88014rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespacerclone
CVE-2026-88013rclone: http backend forwards custom/auth headers to a different host on redirectrclone
CVE-2026-71312rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Executionrclone
CVE-2026-71311rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlinesrclone
CVE-2026-59733rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read…rclone
CVE-2026-59732rclone archive extract allows S3 destination prefix escape via crafted archive pathsrclone
CVE-2026-54572rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remoterclone
CVE-2026-49980Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing…rclone
CVE-2026-41179RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command executionrclone
CVE-2026-41176Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command executionrclone
CVE-2024-52522Rclone Improper Permission and Ownership Handling on Symlink Targets with --links and --metadatarclone
30 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.