THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-fqj9-69pf-6pjg (high) — rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories

[GHSA] GHSA-fqj9-69pf-6pjg (high) — rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories

medgithub_advisoriesPublished 2026-08-05

GHSA-fqj9-69pf-6pjg Severity: high CVE: CVE-2026-59733

rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories

## Summary

`rclone serve restic --private-repos` exists to let one rclone instance host many users' restic backup repositories behind HTTP Basic auth while keeping each user confine

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-fqj9-69pf-6pjg