← All CVEs NewScan detects
medium

CVE-2026-79781

rclone serve s3 path traversal via dot-dot object keys - read and overwrite root-level files

Severity
medium
Affected product
rclone
Affected versions
rclone < 1.74.4
Fixed in
rclone 1.74.4
Added to NewScan
2026-08-26
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints rclone from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-08-26 (/daily-cve). Same version source as the row above (the rclone Server banner). rclone serve s3 before 1.74.4 does not constrain S3 object keys, so dot-dot segments escape the served root to read and overwrite arbitrary files (GHSA-8v25-v8p6-qf7v). Version-match only: exercising the traversal writes to the target's filesystem, which we never do; the banner gate is the safe signal. The generic traversal probe may also reach it in-band on a `serve s3` surface, but that is engine, not this row.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →