Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-71312

Опубликовано: 05 авг. 2026
Источник: redhat
CVSS3: 8
EPSS Низкий

Описание

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscapeShellPath escapes only ASCII apostrophe even though PowerShell treats U+2018, U+2019, U+201A, and U+201B as single-quote delimiters, allowing an attacker-controlled filename to terminate the intended path literal and append PowerShell statements that execute as the victim SSH account when server-side hashing is invoked. This issue is fixed in v1.75.0.

A flaw was found in rclone, a command-line program for syncing files. This vulnerability allows a remote attacker to execute arbitrary commands on the server when processing SFTP paths. By crafting a malicious filename that uses specific Unicode single-quote characters, an attacker can bypass security measures and inject PowerShell commands. This can lead to unauthorized command execution under the victim's SSH account during server-side hashing operations.

Отчет

This is an Important vulnerability in rclone, a command-line file synchronization program, that allows for server-side command execution. An attacker can craft malicious SFTP filenames containing Unicode smart quotes to inject and execute arbitrary PowerShell commands on the system running rclone. This occurs when server-side hashing operations are invoked, potentially leading to compromise of the victim's SSH account.

Меры по смягчению последствий

avoid connecting rclone to SFTP servers that use PowerShell as their SSH command shell, or disable server-side hashing with --sftp-disable-hashcheck. Do not process files from untrusted sources on SFTP remotes backed by PowerShell.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2511773github.com/rclone/rclone: rclone: Server-Side Command Execution via Malicious SFTP Filenames

EPSS

Процентиль: 20%
0.00276
Низкий

8 High

CVSS3

Связанные уязвимости

CVSS3: 8
ubuntu
26 дней назад

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscapeShellPath escapes only ASCII apostrophe even though PowerShell treats U+2018, U+2019, U+201A, and U+201B as single-quote delimiters, allowing an attacker-controlled filename to terminate the intended path literal and append PowerShell statements that execute as the victim SSH account when server-side hashing is invoked. This issue is fixed in v1.75.0.

CVSS3: 8
nvd
26 дней назад

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscapeShellPath escapes only ASCII apostrophe even though PowerShell treats U+2018, U+2019, U+201A, and U+201B as single-quote delimiters, allowing an attacker-controlled filename to terminate the intended path literal and append PowerShell statements that execute as the victim SSH account when server-side hashing is invoked. This issue is fixed in v1.75.0.

CVSS3: 8
debian
26 дней назад

rclone is a command-line program to sync files and directories to and ...

CVSS3: 8
github
26 дней назад

rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution

EPSS

Процентиль: 20%
0.00276
Низкий

8 High

CVSS3