THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8v25-v8p6-qf7v (medium) — rclone: Path traversal in serve s3 allows reading and overwriting root-level files

[GHSA] GHSA-8v25-v8p6-qf7v (medium) — rclone: Path traversal in serve s3 allows reading and overwriting root-level files

medgithub_advisoriesPublished 2026-08-05

GHSA-8v25-v8p6-qf7v Severity: medium CVE: None

rclone: Path traversal in serve s3 allows reading and overwriting root-level files

### Summary

rclone serve s3 allows a client to read and write files at the root of the remote which would normally be inaccessible by using dot-dot path segments in the object key. It does not allow reading files outside of the root. A request such as GET /bucket/..

Original source: https://github.com/advisories/GHSA-8v25-v8p6-qf7v