Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-70460

Опубликовано: 13 авг. 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under the module root, or who can exploit a pre-existing trusted symlink, can direct file writes to locations outside the intended module root, achieving arbitrary file write relative to the module root parent.

EPSS

Процентиль: 37%
0.00448
Низкий

8.1 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.1
ubuntu
18 дней назад

rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under the module root, or who can exploit a pre-existing trusted symlink, can direct file writes to locations outside the intended module root, achieving arbitrary file write relative to the module root parent.

CVSS3: 8.1
redhat
18 дней назад

rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under the module root, or who can exploit a pre-existing trusted symlink, can direct file writes to locations outside the intended module root, achieving arbitrary file write relative to the module root parent.

CVSS3: 8.1
msrc
8 дней назад

rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink

CVSS3: 8.1
debian
18 дней назад

rsync 2.3.3 before 3.5.0contains a path traversal vulnerability that a ...

suse-cvrf
11 дней назад

Security update for rsync

EPSS

Процентиль: 37%
0.00448
Низкий

8.1 High

CVSS3

Дефекты

CWE-22