Official source evidencegithub.comVersioned article
Official source article · github.com

Release rclone v1.75.1 · rclone/rclone · GitHub

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publishergithub.com
Article IDNo stable ID in source URL
Verified snapshot26 Sept 2026, 20:28 UTC
Linked CVEs6

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2026-88016rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
  • CVE-2026-88017rclone: FTP cross-session auth-proxy backend confusion
  • CVE-2026-88018rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
  • CVE-2026-88013rclone: http backend forwards custom/auth headers to a different host on redirect
  • CVE-2026-88014rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
  • CVE-2026-88015rclone local: crafted Range request against a translated symlink panics (DoS)

Source and provenance

Original title: Release rclone v1.75.1 · rclone/rclone · GitHub. Captured 26 Sept 2026, 20:28 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗