THREAT OPS › Threat News › [GHSA] GHSA-f8g7-2xjc-7mfh (medium) — rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
[GHSA] GHSA-f8g7-2xjc-7mfh (medium) — rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
GHSA-f8g7-2xjc-7mfh Severity: medium CVE: CVE-2026-88016
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
## Summary With `-l/--links`, rclone's local backend recreates a source `.rclonelink` object as a real symlink at the destination **verbatim** (preserved by design for faithful backups). Directory-metadata appl
Indicators of compromise
- CVE-2026-88016cve
- CVE-2024-52522cve
- CVE-2026-54572cve
Original source: https://github.com/advisories/GHSA-f8g7-2xjc-7mfh