---
id: GO-2026-6189
aliases:
  - GHSA-8v25-v8p6-qf7v
title: Path traversal in serve s3 in github.com/rclone/rclone
summary: Path traversal in serve s3 in github.com/rclone/rclone
severity: none
vendor: rclone
product: github.com/rclone/rclone
ecosystem: go
affected:
  - github.com/rclone/rclone < 1.74.4
patched:
  - github.com/rclone/rclone 1.74.4
published: '2026-08-18'
updated: '2026-08-18'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GO-2026-6189'
references:
  - url: 'https://github.com/rclone/rclone/security/advisories/GHSA-8v25-v8p6-qf7v'
  - url: >-
      https://github.com/rclone/rclone/commit/83d1e62aa9e0dbd10a5d7eb34c117ae997268cdf
  - url: >-
      https://github.com/rclone/rclone/commit/c89b766cf417fddbe7eace40d31262ecb85bfa93
  - url: 'https://github.com/rclone/rclone/releases/tag/v1.74.4'
tags:
  - osv
  - go
ingestedAt: '2026-08-18T19:21:39.472Z'
---

## Overview

Path traversal in serve s3 in github.com/rclone/rclone

## Affected packages

- `github.com/rclone/rclone < 1.74.4`

## Remediation

Upgrade to a patched release:

- `github.com/rclone/rclone 1.74.4`
