{"id":"CVE-2026-53783","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-53783","summary":"rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced…","details":"rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting a symlink for a path component after validation but before transfer processing. Attackers can additionally leverage unrestricted flags such as --copy-unsafe-links, -D, and --log-file through rrsync to read or write files outside the permitted directory subtree.","published":"2026-08-13T15:19:41.913","modified":"2026-08-13T15:19:41.913","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/RsyncProject/rsync/releases/tag/v3.5.0"},{"type":"WEB","url":"https://github.com/RsyncProject/rsync/security/advisories/GHSA-9cgc-64g4-3gv5"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/rsync-toctou-race-condition-directory-escape-via-rrsync"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-13T15:19:41.913"}}