THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-p6m2-r3w9-mpxw (medium) — rclone local: crafted Range request against a translated symlink panics (DoS)

[GHSA] GHSA-p6m2-r3w9-mpxw (medium) — rclone local: crafted Range request against a translated symlink panics (DoS)

medgithub_advisoriesPublished 2026-09-10

GHSA-p6m2-r3w9-mpxw Severity: medium CVE: CVE-2026-88015

rclone local: crafted Range request against a translated symlink panics (DoS)

### Summary When `backend/local` is used with `--links`/`-l` (or the `links=true` config option), each symlink is exposed as an rclone object whose content is the target path string, suffixed `.rclonelink`. `Object.Open()` decodes an incoming `fs.RangeOption` via

Indicators of compromise

Original source: https://github.com/advisories/GHSA-p6m2-r3w9-mpxw