Bug 2500717 (CVE-2026-59732) - CVE-2026-59732 rclone: Rclone: File overwrite via path traversal during archive extraction
Summary: CVE-2026-59732 rclone: Rclone: File overwrite via path traversal during archi...
Keywords:
Status: NEW
Alias: CVE-2026-59732
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-14 22:02 UTC by OSIDB Bzimport
Modified: 2026-07-29 13:28 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-14 22:02:23 UTC
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone archive extract can write extracted files outside the user-selected destination prefix when extracting a crafted archive containing parent path components such as ../, allowing creation or overwrite of sibling objects in the same bucket or path scope. This issue is fixed in version 1.74.4.


Note You need to log in before you can comment on or make changes to this bug.