THREAT OPS › Threat News › [GHSA] GHSA-8c48-q9wj-3w37 (medium) — rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines
[GHSA] GHSA-8c48-q9wj-3w37 (medium) — rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines
GHSA-8c48-q9wj-3w37 Severity: medium CVE: CVE-2026-71311
rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines
## 1. Summary
A valid but nondefault FTP filename encoding can restore raw CR/LF immediately before an attacker-controlled path is interpolated into the line-oriented FTP control channel. The dependency does not reject CR or LF in command arguments
MITRE ATT&CK techniques
- Standard EncodingT1132.001
Indicators of compromise
- a0c09f1381ae93e2a9a33c529d170186c61ad058sha1
- 961266888fe797390c535386f3b3aa46f4853602sha1
- CVE-2026-71311cve
Original source: https://github.com/advisories/GHSA-8c48-q9wj-3w37