THREAT OPS › Threat News › [GHSA] GHSA-c476-6w5q-jw77 (high) — rclone: FTP cross-session auth-proxy backend confusion
[GHSA] GHSA-c476-6w5q-jw77 (high) — rclone: FTP cross-session auth-proxy backend confusion
GHSA-c476-6w5q-jw77 Severity: high CVE: CVE-2026-88017
rclone: FTP cross-session auth-proxy backend confusion
## Summary
The FTP auth-proxy driver stores one obscured password per username in a server-wide map. It does not bind the credential or returned VFS to the authenticated FTP session. If two accepted credentials use the same username but resolve to different proxy backends, the later log
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- 5629f2668c69149bf3d9d8e2a25bb32a2648606esha1
- CVE-2026-88017cve
- goftp.iodomain
Original source: https://github.com/advisories/GHSA-c476-6w5q-jw77