When the syncing of symbolic links is enabled, either through the -l or -a (--archive) flags, a malicious server can make the client write arbitrary files outside of the destination directory.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:2600 https://access.redhat.com/errata/RHSA-2025:2600
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:7050 https://access.redhat.com/errata/RHSA-2025:7050