Source: rclone
Version: 1.69.3+dfsg-3
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for rclone.

CVE-2026-54572[0]:
| Rclone is a command-line program to sync files and directories to
| and from different cloud storage providers. Prior to 1.74.4, with
| -l/--links, rclone serializes symlinks as .rclonelink text objects
| and recreates them on a local destination without validating the
| target, allowing an attacker-controlled remote to plant an escaping
| symlink and cause a following object write to land outside the
| destination with attacker-chosen contents. This issue is fixed in
| version 1.74.4.


CVE-2026-59732[1]:
| Rclone is a command-line program to sync files and directories to
| and from different cloud storage providers. Prior to 1.74.4, rclone
| archive extract can write extracted files outside the user-selected
| destination prefix when extracting a crafted archive containing
| parent path components such as ../, allowing creation or overwrite
| of sibling objects in the same bucket or path scope. This issue is
| fixed in version 1.74.4.


CVE-2026-59733[2]:
| Rclone is a command-line program to sync files and directories to
| and from different cloud storage providers. Prior to 1.74.4, rclone
| serve restic --private-repos enforces authorization using the routed
| user path segment while building the backend object key from the raw
| uncleaned URL path, allowing an authenticated user to include .. in
| a request such as //..//config and read, overwrite, or delete
| another user's private repository on backends that clean path
| components. This issue is fixed in version 1.74.4.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-54572
    https://www.cve.org/CVERecord?id=CVE-2026-54572
[1] https://security-tracker.debian.org/tracker/CVE-2026-59732
    https://www.cve.org/CVERecord?id=CVE-2026-59732
[2] https://security-tracker.debian.org/tracker/CVE-2026-59733
    https://www.cve.org/CVERecord?id=CVE-2026-59733

Regards,
Salvatore

Reply via email to