THREAT OPS › Threat News › [GHSA] GHSA-4vr5-p2gc-h23p (medium) — rclone archive extract allows S3 destination prefix escape via crafted archive paths
[GHSA] GHSA-4vr5-p2gc-h23p (medium) — rclone archive extract allows S3 destination prefix escape via crafted archive paths
GHSA-4vr5-p2gc-h23p Severity: medium CVE: CVE-2026-59732
rclone archive extract allows S3 destination prefix escape via crafted archive paths
### Summary
`rclone archive extract` can write extracted files outside the user-selected destination prefix when extracting a crafted archive. A malicious archive entry containing parent path components such as `../` can escape the requested extraction pr
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-59732cve
Original source: https://github.com/advisories/GHSA-4vr5-p2gc-h23p