CVE-2026-54572

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
14/07/2026
Last modified:
17/07/2026

Description

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks as .rclonelink text objects and recreates them on a local destination without validating the target, allowing an attacker-controlled remote to plant an escaping symlink and cause a following object write to land outside the destination with attacker-chosen contents. This issue is fixed in version 1.74.4.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:* 1.74.4 (excluding)