THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-p569-5gjg-9cmj (critical) — rclone: RC per-server auth-proxy bypass

[GHSA] GHSA-p569-5gjg-9cmj (critical) — rclone: RC per-server auth-proxy bypass

highgithub_advisoriesPublished 2026-09-10

GHSA-p569-5gjg-9cmj Severity: critical CVE: CVE-2026-88044

rclone: RC per-server auth-proxy bypass

## Summary

`serve/start` accepts protocol options in a per-server `proxyOpt` object. The FTP and S3 RC adapters parse that object and pass it to their server constructors, but the constructors decide whether proxy authentication is enabled by checking the process-global `proxy.Opt.AuthProxy` inste

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-p569-5gjg-9cmj