{"id":"CVE-2026-54572","aliases":["BIT-rclone-2026-54572","GHSA-cf44-9pgv-m4xc","GO-2026-6191"],"url":"https://o3.security/vulnerability/CVE-2026-54572","summary":"rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote","details":"Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks as .rclonelink text objects and recreates them on a local destination without validating the target, allowing an attacker-controlled remote to plant an escaping symlink and cause a following object write to land outside the destination with attacker-chosen contents. This issue is fixed in version 1.74.4.","published":"2026-07-14T21:37:41.882Z","modified":"2026-08-18T17:24:12.678539054Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/rclone/rclone","fixedVersion":"1.74.4"}],"fix":{"url":"https://github.com/rclone/rclone/commit/1154afebee986180b489084d38e2a0c578751498","label":"rclone/rclone@1154afe"},"references":[{"type":"WEB","url":"https://github.com/rclone/rclone/releases/tag/v1.74.4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54572.json"},{"type":"ADVISORY","url":"https://github.com/rclone/rclone/security/advisories/GHSA-cf44-9pgv-m4xc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54572"},{"type":"FIX","url":"https://github.com/rclone/rclone/commit/1154afebee986180b489084d38e2a0c578751498"},{"type":"FIX","url":"https://github.com/rclone/rclone/commit/874a804f5289517defdd7de68b2a374837080265"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-18T17:24:12.678539054Z"}}