---
id: GO-2026-6190
aliases:
  - GHSA-945v-v9p3-v5xw
title: Unsafe file permission restoration from metadata in github.com/rclone/rclone
summary: Unsafe file permission restoration from metadata in github.com/rclone/rclone
severity: none
vendor: rclone
product: github.com/rclone/rclone
ecosystem: go
affected:
  - github.com/rclone/rclone < 1.74.4
patched:
  - github.com/rclone/rclone 1.74.4
published: '2026-08-18'
updated: '2026-08-18'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GO-2026-6190'
references:
  - url: 'https://github.com/rclone/rclone/security/advisories/GHSA-945v-v9p3-v5xw'
  - url: >-
      https://github.com/rclone/rclone/commit/e58f09739a35774ca82b5211d2377ac0f2051500
  - url: 'https://github.com/rclone/rclone/releases/tag/v1.74.4'
tags:
  - osv
  - go
ingestedAt: '2026-08-18T19:21:39.508Z'
---

## Overview

Unsafe file permission restoration from metadata in github.com/rclone/rclone

## Affected packages

- `github.com/rclone/rclone < 1.74.4`

## Remediation

Upgrade to a patched release:

- `github.com/rclone/rclone 1.74.4`
