THREATOPS
THREAT OPSThreat News › croc: Arbitrary File Deletion via received filename, chainable to RCE (fixed in 11.0.3)

croc: Arbitrary File Deletion via received filename, chainable to RCE (fixed in 11.0.3)

lowoss_secPublished 2026-08-14

<p>Posted by Souiri Anas on Aug 14</p>Hello,<br /> <br /> This reports an arbitrary file deletion vulnerability in croc, the<br /> end-to-end encrypted file transfer tool [1], which can be chained to<br /> remote code execution on the receiving host. The issue is fixed in<br /> croc 11.0.3 [5].<br /> <br /> Affected / fixed<br /> ================<br /> <br /> Product: croc (github.com/schollz/cro

MITRE ATT&CK techniques

Original source: https://seclists.org/oss-sec/2026/q3/496