THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-cf44-9pgv-m4xc (high) — rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote

[GHSA] GHSA-cf44-9pgv-m4xc (high) — rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote

highgithub_advisoriesPublished 2026-08-05

GHSA-cf44-9pgv-m4xc Severity: high CVE: CVE-2026-54572

rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote

### Summary With `-l/--links`, rclone serializes symlinks as `<name>.rclonelink` text objects whose body is the link target. When rclone writes such an object to a local destination, it recreates the symlink with `os.Symlink(<object body>, <

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-cf44-9pgv-m4xc