<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T10:34:23.212996+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-rclone-2026-71312</id>
    <title>BIT-rclone-2026-71312 — rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution</title>
    <updated>2026-10-05T10:34:23.596277+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: rclone</p>
<p>rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscapeShellPath escapes only ASCII apostrophe even though PowerShell treats U+2018, U+2019, U+201A, and U+201B as single-quote delimiters, allowing an attacker-controlled filename to terminate the intended path literal and append PowerShell statements that execute as the victim SSH account when server-side hashing is invoked. This issue is fixed in v1.75.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-rclone-2026-71312"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1125</id>
    <title>certfr-2026-avi-1125 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-05T10:34:23.596341+00:00</updated>
    <content>certfr-2026-avi-1125</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1125"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-349195</id>
    <title>EUVD-2026-349195</title>
    <updated>2026-10-05T10:34:23.596362+00:00</updated>
    <content>EUVD-2026-349195</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-349195"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-71312</id>
    <title>fkie_cve-2026-71312</title>
    <updated>2026-10-05T10:34:23.596375+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscapeShellPath escapes only ASCII apostrophe even though PowerShell treats U+2018, U+2019, U+201A, and U+201B as single-quote delimiters, allowing an attacker-controlled filename to terminate the intended path literal and append PowerShell statements that execute as the victim SSH account when server-side hashing is invoked. This issue is fixed in v1.75.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-71312"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2m8m-jhrm-w6j2</id>
    <title>GHSA-2m8m-jhrm-w6j2 — rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution</title>
    <updated>2026-10-05T10:34:23.596398+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/rclone/rclone</p>
<p>## 1. Summary</p>
<p>rclone interpolates remote SFTP paths into PowerShell hash commands. Its quoting helper escapes only ASCII apostrophe, although PowerShell accepts four Unicode smart quotes as single-quote delimiters. An attacker-controlled filename can therefore terminate the intended path literal and append PowerShell statements executed as the victim's SSH account.</p>
<p>## 2. Affected Assets &amp; Attack Surface</p>
<p>- Audited commit: `a0c09f1381ae93e2a9a33c529d170186c61ad058`
- Backend: `backend/sftp`
- Relevant code:
  - `backend/sftp/sftp.go:1802-1812` — PowerShell hash commands
  - `backend/sftp/sftp.go:1663-1699` — `Fs.run`
  - `backend/sftp/sftp.go:1988-2067` — `Object.Hash`
  - `backend/sftp/sftp.go:2071-2090` — `quoteOrEscapeShellPath`
- Exposed input: remote filename controlled by an SFTP collaborator, upstream storage source, or other party able to create or rename files.
- Required execution context: PowerShell as the SSH command shell, SSH exec enabled, and server-side hashing invoked.</p>
<p>## 3. Technical Root Cause Analysis</p>
<p>For PowerShell, `quoteOrEscapeShellPath` wraps a path in ASCII apostrophes and doubles only `U+0027`:</p>
<p>```go
return "'" + strings.ReplaceAll(shellPath, "'", "''") + "'", nil
```</p>
<p>Windows PowerShell also treats `U+2018`, `U+2019`, `U+201A`, and `U+201B` as single-quote delimiters. Those characters pass through the rclone encoder and can close the quoted path. The completed string is sent as shell source through an SSH exec request.</p>
<p>The security boundary f…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2m8m-jhrm-w6j2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-71312</id>
    <title>UBUNTU-CVE-2026-71312</title>
    <updated>2026-10-05T10:34:23.596482+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: rclone, Ubuntu:Pro:20.04:LTS: rclone, Ubuntu:Pro:22.04:LTS: rclone, Ubuntu:Pro:24.04:LTS: rclone, Ubuntu:Pro:26.04:LTS: rclone</p>
<p>rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscapeShellPath escapes only ASCII apostrophe even though PowerShell treats U+2018, U+2019, U+201A, and U+201B as single-quote delimiters, allowing an attacker-controlled filename to terminate the intended path literal and append PowerShell statements that execute as the victim SSH account when server-side hashing is invoked. This issue is fixed in v1.75.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-71312"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2679</id>
    <title>WID-SEC-W-2026-2679 — rclone: Mehrere Schwachstellen</title>
    <updated>2026-10-05T10:34:23.596560+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in rclone ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, und um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2679"/>
  </entry>
</feed>
