Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-54572

Опубликовано: 14 июл. 2026
Источник: debian
EPSS Низкий

Описание

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks as .rclonelink text objects and recreates them on a local destination without validating the target, allowing an attacker-controlled remote to plant an escaping symlink and cause a following object write to land outside the destination with attacker-chosen contents. This issue is fixed in version 1.74.4.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rcloneunfixedpackage

Примечания

  • https://github.com/rclone/rclone/security/advisories/GHSA-cf44-9pgv-m4xc

  • Fixed by: https://github.com/rclone/rclone/commit/874a804f5289517defdd7de68b2a374837080265 (v1.74.4)

EPSS

Процентиль: 23%
0.00309
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
21 день назад

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks as .rclonelink text objects and recreates them on a local destination without validating the target, allowing an attacker-controlled remote to plant an escaping symlink and cause a following object write to land outside the destination with attacker-chosen contents. This issue is fixed in version 1.74.4.

CVSS3: 7.5
redhat
21 день назад

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks as .rclonelink text objects and recreates them on a local destination without validating the target, allowing an attacker-controlled remote to plant an escaping symlink and cause a following object write to land outside the destination with attacker-chosen contents. This issue is fixed in version 1.74.4.

CVSS3: 7.5
nvd
21 день назад

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks as .rclonelink text objects and recreates them on a local destination without validating the target, allowing an attacker-controlled remote to plant an escaping symlink and cause a following object write to land outside the destination with attacker-chosen contents. This issue is fixed in version 1.74.4.

suse-cvrf
13 дней назад

Security update for rclone

EPSS

Процентиль: 23%
0.00309
Низкий