CVE-2026-79781
rclone serve s3 path traversal via dot-dot object keys - read and overwrite root-level files
- Severity
- medium
- Affected product
- rclone
- Affected versions
- rclone < 1.74.4
- Fixed in
- rclone 1.74.4
- Added to NewScan
- 2026-08-26
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints rclone from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-08-26 (/daily-cve). Same version source as the row above (the rclone Server banner). rclone serve s3 before 1.74.4 does not constrain S3 object keys, so dot-dot segments escape the served root to read and overwrite arbitrary files (GHSA-8v25-v8p6-qf7v). Version-match only: exercising the traversal writes to the target's filesystem, which we never do; the banner gate is the safe signal. The generic traversal probe may also reach it in-band on a `serve s3` surface, but that is engine, not this row.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →