CVE-2026-59733

EUVD-2026-44533
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path segment while building the backend object key from the raw uncleaned URL path, allowing an authenticated user to include .. in a request such as //..//config and read, overwrite, or delete another user's private repository on backends that clean path components. This issue is fixed in version 1.74.4.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 40.4%
Affected Products (NVD)
VendorProductVersion
rclonerclone
𝑥
< 1.74.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
rclone
bookworm
vulnerable
bullseye
vulnerable
sid
vulnerable
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
rclone
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
rclone
Amazon Linux 2
0:1.55.1-1.amzn2.0.10
fixed
Amazon Linux 2023
0:1.74.3-83.amzn2023
fixed
rclone-debuginfo
Amazon Linux 2
0:1.55.1-1.amzn2.0.10
fixed
Amazon Linux 2023
0:1.74.3-83.amzn2023
fixed
rclone-debugsource
Amazon Linux 2023
0:1.74.3-83.amzn2023
fixed