THREAT OPS › Threat News › croc: Arbitrary File Deletion via received filename, chainable to RCE (fixed in 11.0.3)
croc: Arbitrary File Deletion via received filename, chainable to RCE (fixed in 11.0.3)
<p>Posted by Souiri Anas on Aug 14</p>Hello,<br /> <br /> This reports an arbitrary file deletion vulnerability in croc, the<br /> end-to-end encrypted file transfer tool [1], which can be chained to<br /> remote code execution on the receiving host. The issue is fixed in<br /> croc 11.0.3 [5].<br /> <br /> Affected / fixed<br /> ================<br /> <br /> Product: croc (github.com/schollz/cro
MITRE ATT&CK techniques
- File DeletionT1070.004
Original source: https://seclists.org/oss-sec/2026/q3/496