Vulnerabilidades en rclone

12 resultados
Análisis Vexday

O rclone possui 7 CVEs catalogadas, com 4 publicadas nos últimos 90 dias, indicando atividade recente de descoberta de vulnerabilidades. Nenhuma das falhas está sob exploração ativa conhecida, mas 3 são classificadas como críticas, predominantemente relacionadas a autenticação insuficiente (CWE-306). O risco permanece moderado, exigindo atenção às atualizações recentes para mitigar as falhas críticas identificadas.

CVE-2026-41176CRITICALRclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command executionEPSS 32.7%CVE-2026-41179CRITICALRClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command executionEPSS 8.6%CVE-2026-49980CRITICALRclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fixEPSS 0.7%CVE-2026-59733HIGHrclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositoriesEPSS 0.4%CVE-2026-71310MEDIUMrclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone MemoryEPSS 0.4%CVE-2026-71309HIGHrclone: Incomplete path validation allows backend root escape in serve resticEPSS 0.3%CVE-2026-54572HIGHrclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remoteEPSS 0.3%CVE-2026-71312HIGHrclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command ExecutionEPSS 0.3%CVE-2026-71313MEDIUMrclone: Local Encoding Path TraversalEPSS 0.3%CVE-2026-71311MEDIUMrclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves NewlinesEPSS 0.2%CVE-2024-52522MEDIUMRclone Improper Permission and Ownership Handling on Symlink Targets with --links and --metadataEPSS 0.2%CVE-2026-59732MEDIUMrclone archive extract allows S3 destination prefix escape via crafted archive pathsEPSS 0.2%