{"schema_version":"1.9.0","id":"BIT-rclone-2026-54572","published":"2026-07-19T23:51:44.432Z","modified":"2026-09-08T08:48:19.062465365Z","aliases":["CVE-2026-54572","GHSA-cf44-9pgv-m4xc","GO-2026-6191"],"summary":"rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote","details":"Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks as .rclonelink text objects and recreates them on a local destination without validating the target, allowing an attacker-controlled remote to plant an escaping symlink and cause a following object write to land outside the destination with attacker-chosen contents. This issue is fixed in version 1.74.4.","affected":[{"package":{"name":"rclone","ecosystem":"Bitnami","purl":"pkg:bitnami/rclone"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.74.4"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/rclone/BIT-rclone-2026-54572.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L"}]}],"references":[{"type":"FIX","url":"https://github.com/rclone/rclone/commit/1154afebee986180b489084d38e2a0c578751498"},{"type":"FIX","url":"https://github.com/rclone/rclone/commit/874a804f5289517defdd7de68b2a374837080265"},{"type":"ARTICLE","url":"https://github.com/rclone/rclone/releases/tag/v1.74.4"},{"type":"ADVISORY","url":"https://github.com/rclone/rclone/security/advisories/GHSA-cf44-9pgv-m4xc"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54572"}],"database_specific":{"cpes":["cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:*","cpe:2.3:a:rclone:rclone:*:*:*:*:*:go:*:*"],"severity":"High"}}