THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-7p4m-qxvv-g567 (medium) — rclone: Local Encoding Path Traversal

[GHSA] GHSA-7p4m-qxvv-g567 (medium) — rclone: Local Encoding Path Traversal

highgithub_advisoriesPublished 2026-08-05

GHSA-7p4m-qxvv-g567 Severity: medium CVE: CVE-2026-71313

rclone: Local Encoding Path Traversal

## Summary

The local backend relies on its configurable filename encoder to prevent remote filename data from becoming operating-system path syntax. If a local destination uses an encoding that omits `Dot`, such as `Slash`, `None`, or `Raw`, a remote object's standard-encoded `..` component is decoded

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-7p4m-qxvv-g567