THREAT OPS › Threat News › [GHSA] GHSA-38xv-hf3p-h7mq (medium) — rclone: source object names can escape the configured root on upload
[GHSA] GHSA-38xv-hf3p-h7mq (medium) — rclone: source object names can escape the configured root on upload
GHSA-38xv-hf3p-h7mq Severity: medium CVE: CVE-2026-88046
rclone: source object names can escape the configured root on upload
### Summary
Multiple backends, when given a specially crafted object to copy, can escape the backend confinement.
| Backend | Keep/Close | Per-backend severity | |---|---|---| | sftp | Medium | Real filesystem escape, fires under default encoding. | | smb | Low-Medium |
Indicators of compromise
- CVE-2026-88046cve
Original source: https://github.com/advisories/GHSA-38xv-hf3p-h7mq