THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-f8g7-2xjc-7mfh (medium) — rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination

[GHSA] GHSA-f8g7-2xjc-7mfh (medium) — rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination

medgithub_advisoriesPublished 2026-09-10

GHSA-f8g7-2xjc-7mfh Severity: medium CVE: CVE-2026-88016

rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination

## Summary With `-l/--links`, rclone's local backend recreates a source `.rclonelink` object as a real symlink at the destination **verbatim** (preserved by design for faithful backups). Directory-metadata appl

Indicators of compromise

Original source: https://github.com/advisories/GHSA-f8g7-2xjc-7mfh