Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-59733 |
|
Path Traversal in github.com/rclone/rclone (CVE-2026-59733)
path traversal in github.com/rclone/rclone (CVE-2026-59733). Successful exploitation can lead to full system takeover. Exploitable via `GET /test/../victim/config`. Mitigation: upgrade to `1.74.4` or later.
|
| CVE-2026-59732 |
|
Path Traversal in github.com/rclone/rclone (CVE-2026-59732)
path traversal in github.com/rclone/rclone (CVE-2026-59732). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /bucket/safe/prefix/escaped-from-prefix.txt`. Mitigation: upgrade to `1.74.4` or later.
|
| CVE-2026-54572 |
|
Vulnerability in github.com/rclone/rclone (CVE-2026-54572)
vulnerability in github.com/rclone/rclone (CVE-2026-54572). Data can be tampered with by attackers. Exploitable via ``mkdirAll``. Mitigation: upgrade to `1.74.4` or later.
|
| CVE-2026-49980 |
|
Vulnerability in github.com/rclone/rclone (CVE-2026-49980)
vulnerability in github.com/rclone/rclone (CVE-2026-49980). Successful exploitation can lead to full system takeover. Exploitable via ``GET``. Mitigation: upgrade to `1.74.3` or later.
|
| CVE-2026-41176 |
|
Vulnerability in rclone (CVE-2026-41176)
vulnerability in rclone (CVE-2026-41176). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.73.5` or later.
|
| CVE-2026-41179 |
|
OS Command Injection in github.com/rclone/rclone (CVE-2026-41179)
OS command injection in github.com/rclone/rclone (CVE-2026-41179). Successful exploitation can lead to full system takeover. Exploitable via ``bearer_token_command``. Mitigation: upgrade to `1.73.5` or later.
|