CVE-2026-88016

HIGH CVSS 3.1: 7.1 EPSS 0.19%
Updated Sep 15, 2026
Rclone
Parameter Value
CVSS 7.1 (HIGH)
Affected Versions before 1.75.1
Fixed In 1.75.1
Type CWE-59 (Improper Link Resolution), CWE-281
Vendor Rclone
Public PoC No

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, when backend/local runs with --links, a source .rclonelink object can plant a symlink in the destination and later directory metadata is applied through that path. MkdirMetadata, writeMetadataToFile, and setTimes operate when Directory.translatedLink=false, so os.Chown, os.Chmod, os.Chtimes, and birth-time handling can bypass os.Root confinement and follow the symlink. An attacker controlling source contents can therefore apply selected ownership, permissions, modification times, or birth times to a file or directory outside the destination, with --metadata required for chmod and chown while modification time is applied by the normal directory workflow.

This issue is fixed in version 1.75.1.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
High
Complete data modification
Availability
Low
Partial disruption

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Rclone Rclone
cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:*
1.75.1