THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-45pq-889g-fcgh (high) — rclone: Incomplete path validation allows backend root escape in serve restic

[GHSA] GHSA-45pq-889g-fcgh (high) — rclone: Incomplete path validation allows backend root escape in serve restic

highgithub_advisoriesPublished 2026-08-05

GHSA-45pq-889g-fcgh Severity: high CVE: CVE-2026-71309

rclone: Incomplete path validation allows backend root escape in serve restic

## Summary

`rclone serve restic` does not correctly reject URL paths beginning with `../`. On affected backends, an attacker who can access the REST endpoint can read, create, overwrite, or delete objects outside the path configured by the operator.

The issue aff

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-45pq-889g-fcgh