THREAT OPS › Threat News › [GHSA] GHSA-cf44-9pgv-m4xc (high) — rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote
[GHSA] GHSA-cf44-9pgv-m4xc (high) — rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote
GHSA-cf44-9pgv-m4xc Severity: high CVE: CVE-2026-54572
rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote
### Summary With `-l/--links`, rclone serializes symlinks as `<name>.rclonelink` text objects whose body is the link target. When rclone writes such an object to a local destination, it recreates the symlink with `os.Symlink(<object body>, <
MITRE ATT&CK techniques
- Link TargetT1608.005
Indicators of compromise
- CVE-2026-54572cve
- https://downloads.rclone.org/v1.74.3/rclone-v1.74.3-linux-amd64.zipurl
- http://127.0.0.1:38080url
Original source: https://github.com/advisories/GHSA-cf44-9pgv-m4xc