THREAT OPS › Threat News › [GHSA] GHSA-2m8m-jhrm-w6j2 (high) — rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution
[GHSA] GHSA-2m8m-jhrm-w6j2 (high) — rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution
GHSA-2m8m-jhrm-w6j2 Severity: high CVE: CVE-2026-71312
rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution
## 1. Summary
rclone interpolates remote SFTP paths into PowerShell hash commands. Its quoting helper escapes only ASCII apostrophe, although PowerShell accepts four Unicode smart quotes as single-quote delimiters. An attacker-controlled filename ca
MITRE ATT&CK techniques
Indicators of compromise
- a0c09f1381ae93e2a9a33c529d170186c61ad058sha1
- CVE-2026-71312cve
Original source: https://github.com/advisories/GHSA-2m8m-jhrm-w6j2