rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote
Published Jul 14, 2026
8.8
HIGHCVSS 3.1
EPSS 0.40%
Description
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks as .rclonelink text objects and recreates them on a local destination without validating the target, allowing an attacker-controlled remote to plant an escaping symlink and cause a following object write to land outside the destination with attacker-chosen contents. This issue is fixed in version 1.74.4.
Affected products
-
- Version < 1.74.4StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
github.com/rclone/rclone
Go
Introduced 0 Fixed 1.74.4
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/rclone/rclone | 0 | 1.74.4 |
Remediation
Red Hat statement
Rclone's -l/--links option serializes symbolic links encountered during a sync as `.rclonelink` text objects containing the link target, and later recreates those links on the destination. Prior to 1.74.4, rclone did not validate that a stored link target stays within the intended destination tree before recreating it. A remote storage backend under an attacker's control can therefore supply a crafted `.rclonelink` object whose target escapes the destination directory (e.g. via a `../` traversal or an absolute path), causing a subsequent write during the same or a later sync to be redirected outside the intended destination with attacker-chosen content. Exploitation requires that the victim explicitly enable symlink handling (-l/--links) and initiate a sync against a remote the attacker can influence (e.g. a shared/untrusted cloud storage bucket, or a compromised legitimate remote); it is not exploitable against a default rclone configuration or against a fully trusted remote. This combination of required non-default configuration and required user-initiated action from an untrusted source is reflected in Red Hat's CVSS vector (AC:H, UI:R). The confidentiality impact is limited to what can be inferred from being able to overwrite files (e.g. tampering with a config file that is later read), while the primary impact is to integrity (arbitrary attacker-controlled file content written outside the sync destination) and, secondarily, availability (overwriting or corrupting files outside the destination). This issue is corrected upstream in rclone 1.74.4, which validates a `.rclonelink` target stays within the destination before recreating it.
Red Hat mitigation
Upgrade to rclone 1.74.4 or later, which validates symlink targets before recreating them and rejects links that would escape the destination directory. If an immediate upgrade is not possible, mitigate by avoiding the vulnerable code path: do not use the -l/--links command-line option when syncing to or from a remote that is not fully trusted, since this is what enables rclone to serialize and recreate symlinks in the first place.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L
1 other source (GHSA) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Jul 15, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
Jul-Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 0.40% (0.00404) | 32.39th | v5 (v2026.06.15) |
| Jul 15, 2026 | 0.34% (0.00343) | 26.49th | v5 (v2026.06.15) |
References (9)
- https://access.redhat.com/security/cve/CVE-2026-54572 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2500758 Issue Tracking
- https://github.com/advisories/GHSA-cf44-9pgv-m4xc Advisory
- https://github.com/rclone/rclone/commit/1154afebee986180b489084d38e2a0c578751498 x_refsource_MISCPatch
- https://github.com/rclone/rclone/commit/874a804f5289517defdd7de68b2a374837080265 x_refsource_MISCPatch
- https://github.com/rclone/rclone/releases/tag/v1.74.4 x_refsource_MISCRelease Notes
- https://github.com/rclone/rclone/security/advisories/GHSA-cf44-9pgv-m4xc exploitx_refsource_CONFIRMMitigationVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-54572
- https://www.cve.org/CVERecord?id=CVE-2026-54572
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-54572 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2500758 | Issue Tracking | |
| https://github.com/advisories/GHSA-cf44-9pgv-m4xc | Advisory | |
| https://github.com/rclone/rclone/commit/1154afebee986180b489084d38e2a0c578751498 | x_refsource_MISCPatch | |
| https://github.com/rclone/rclone/commit/874a804f5289517defdd7de68b2a374837080265 | x_refsource_MISCPatch | |
| https://github.com/rclone/rclone/releases/tag/v1.74.4 | x_refsource_MISCRelease Notes | |
| https://github.com/rclone/rclone/security/advisories/GHSA-cf44-9pgv-m4xc | exploitx_refsource_CONFIRMMitigationVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-54572 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-54572 |
Change history (0)
No recorded changes yet.