Vulnerability Description
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 until v1.75.0, the local backend in backend/local/local.go relies on the configurable filename encoder to prevent remote filename data from becoming operating-system path syntax, so a local destination using Slash, None, Raw, or on Windows an encoding that preserves backslash can decode a standard-encoded fullwidth dot-dot component or native backslash form into an actual parent-directory component before filepath.Join resolves it outside the configured local root, allowing an attacker-controlled source object to create or overwrite files outside the selected destination directory as the rclone process. This issue is fixed in v1.75.0.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/rclone/rclone/commit/6a69713864b1d8f6edbc03d8af735f9624576d6e
- https://github.com/rclone/rclone/releases/tag/v1.75.0
- https://github.com/rclone/rclone/security/advisories/GHSA-7p4m-qxvv-g567
- https://github.com/rclone/rclone/security/advisories/GHSA-7p4m-qxvv-g567
FAQ
What is CVE-2026-71313?
CVE-2026-71313 is a vulnerability with a CVSS score of 6.9 (MEDIUM). rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 until v1.75.0, the local backend in backend/local/local.go relies on the conf...
How severe is CVE-2026-71313?
CVE-2026-71313 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-71313?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.