THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-2m8m-jhrm-w6j2 (high) — rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution

[GHSA] GHSA-2m8m-jhrm-w6j2 (high) — rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution

highgithub_advisoriesPublished 2026-08-05

GHSA-2m8m-jhrm-w6j2 Severity: high CVE: CVE-2026-71312

rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution

## 1. Summary

rclone interpolates remote SFTP paths into PowerShell hash commands. Its quoting helper escapes only ASCII apostrophe, although PowerShell accepts four Unicode smart quotes as single-quote delimiters. An attacker-controlled filename ca

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-2m8m-jhrm-w6j2