Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read and overwrite root-level files by using dot-dot segments in S3 object keys. Attackers can send requests with object keys like ../root-secret.txt to escape the bucket namespace and access files in the serve root directory. | |
| Title | rclone serve s3 Path Traversal via dot-dot object keys | |
| First Time appeared |
Rclone
Rclone rclone |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Rclone
Rclone rclone |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T17:29:20.262Z
Reserved: 2026-08-25T14:32:37.762Z
Link: CVE-2026-79781
Updated: 2026-08-25T17:28:54.289Z
Status : Received
Published: 2026-08-25T16:17:30.080
Modified: 2026-08-25T18:18:06.850
Link: CVE-2026-79781
No data.
OpenCVE Enrichment
Updated: 2026-08-25T17:00:04Z
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')