THREAT OPS › Threat News › [GHSA] GHSA-p569-5gjg-9cmj (critical) — rclone: RC per-server auth-proxy bypass
[GHSA] GHSA-p569-5gjg-9cmj (critical) — rclone: RC per-server auth-proxy bypass
GHSA-p569-5gjg-9cmj Severity: critical CVE: CVE-2026-88044
rclone: RC per-server auth-proxy bypass
## Summary
`serve/start` accepts protocol options in a per-server `proxyOpt` object. The FTP and S3 RC adapters parse that object and pass it to their server constructors, but the constructors decide whether proxy authentication is enabled by checking the process-global `proxy.Opt.AuthProxy` inste
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- 5629f2668c69149bf3d9d8e2a25bb32a2648606esha1
- CVE-2026-88044cve
- http://127.0.0.1:5572url
- http://127.0.0.1:8080url
Original source: https://github.com/advisories/GHSA-p569-5gjg-9cmj