CVE-2026-79783Low· 3.6▾ Sunlitrclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files. When copying with metadata preservati…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 19.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 27.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.1%
Last analysed / modified upstream
rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files. When copying with metadata preservation from an untrusted remote, attackers can plant a setuid binary that escalates privileges to root if rclone runs as root, or to the service account user otherwise.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/rclone/rclone < 1.74.4Patched in:
github.com/rclone/rclone 1.74.4Connected by shared product, vendor, weakness, or advisory.
GHSA-945v-v9p3-v5xwLow· 3.6rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote
GO-2026-6190NoneUnsafe file permission restoration from metadata in github.com/rclone/rclone
CVE-2026-79782Low· 3.1rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host
CVE-2026-79781Medium· 6.5rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read and overwrite root-level files by using dot-dot segments in S3 object keys
CVE-2026-59732Medium· 5.0rclone archive extract allows S3 destination prefix escape via crafted archive paths
CVE-2026-88014Medium· 6.3rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace