THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8c48-q9wj-3w37 (medium) — rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines

[GHSA] GHSA-8c48-q9wj-3w37 (medium) — rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines

highgithub_advisoriesPublished 2026-08-05

GHSA-8c48-q9wj-3w37 Severity: medium CVE: CVE-2026-71311

rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines

## 1. Summary

A valid but nondefault FTP filename encoding can restore raw CR/LF immediately before an attacker-controlled path is interpolated into the line-oriented FTP control channel. The dependency does not reject CR or LF in command arguments

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-8c48-q9wj-3w37