THREAT OPS › Threat News › [GHSA] GHSA-7p4m-qxvv-g567 (medium) — rclone: Local Encoding Path Traversal
[GHSA] GHSA-7p4m-qxvv-g567 (medium) — rclone: Local Encoding Path Traversal
GHSA-7p4m-qxvv-g567 Severity: medium CVE: CVE-2026-71313
rclone: Local Encoding Path Traversal
## Summary
The local backend relies on its configurable filename encoder to prevent remote filename data from becoming operating-system path syntax. If a local destination uses an encoding that omits `Dot`, such as `Slash`, `None`, or `Raw`, a remote object's standard-encoded `..` component is decoded
MITRE ATT&CK techniques
- Standard EncodingT1132.001
Indicators of compromise
- a0c09f1381ae93e2a9a33c529d170186c61ad058sha1
- c99b2d11edb0986cd2b1190e9fa25a58a3f12661sha1
- CVE-2026-71313cve
Original source: https://github.com/advisories/GHSA-7p4m-qxvv-g567