THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-38xv-hf3p-h7mq (medium) — rclone: source object names can escape the configured root on upload

[GHSA] GHSA-38xv-hf3p-h7mq (medium) — rclone: source object names can escape the configured root on upload

medgithub_advisoriesPublished 2026-09-10

GHSA-38xv-hf3p-h7mq Severity: medium CVE: CVE-2026-88046

rclone: source object names can escape the configured root on upload

### Summary

Multiple backends, when given a specially crafted object to copy, can escape the backend confinement.

| Backend | Keep/Close | Per-backend severity | |---|---|---| | sftp | Medium | Real filesystem escape, fires under default encoding. | | smb | Low-Medium |

Indicators of compromise

Original source: https://github.com/advisories/GHSA-38xv-hf3p-h7mq