BlackTreeCVE IntelligenceOfficial source evidencegithub.comVersioned article
Official source article · github.com
Release rclone v1.75.1 · rclone/rclone · GitHub
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publishergithub.com
Article IDNo stable ID in source URL
Verified snapshot26 Sept 2026, 20:28 UTC
Linked CVEs6
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-88016rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
- CVE-2026-88017rclone: FTP cross-session auth-proxy backend confusion
- CVE-2026-88018rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
- CVE-2026-88013rclone: http backend forwards custom/auth headers to a different host on redirect
- CVE-2026-88014rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
- CVE-2026-88015rclone local: crafted Range request against a translated symlink panics (DoS)
Source and provenance
Original title: Release rclone v1.75.1 · rclone/rclone · GitHub. Captured 26 Sept 2026, 20:28 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗