CVE-2026-71313

MEDIUM

rclone: Local Encoding Path Traversal

Title source: cna
STIX 2.1

Description

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 until v1.75.0, the local backend in backend/local/local.go relies on the configurable filename encoder to prevent remote filename data from becoming operating-system path syntax, so a local destination using Slash, None, Raw, or on Windows an encoding that preserves backslash can decode a standard-encoded fullwidth dot-dot component or native backslash form into an actual parent-directory component before filepath.Join resolves it outside the configured local root, allowing an attacker-controlled source object to create or overwrite files outside the selected destination directory as the rclone process. This issue is fixed in v1.75.0.

Scores

CVSS v3 6.9
EPSS 0.0025
EPSS Percentile 16.8%
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
rclone/rclone 1.51.0 - 1.75.0Go
rclone/rclone >= 1.51.0, < 1.75.0
Published Aug 05, 2026
Tracked Since Aug 06, 2026