<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:21:05 +0000</lastBuildDate>
    <item>
      <title>BIT-rclone-2026-59732 — rclone archive extract allows S3 destination prefix escape via crafted archive paths</title>
      <link>https://cve.radiocsirt.org/vuln/bit-rclone-2026-59732</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: rclone&lt;/p&gt;
&lt;p&gt;Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone archive extract can write extracted files outside the user-selected destination prefix when extracting a crafted archive containing parent path components such as ../, allowing creation or overwrite of sibling objects in the same bucket or path scope. This issue is fixed in version 1.74.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: rclone&lt;/p&gt;
&lt;p&gt;Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone archive extract can write extracted files outside the user-selected destination prefix when extracting a crafted archive containing parent path components such as ../, allowing creation or overwrite of sibling objects in the same bucket or path scope. This issue is fixed in version 1.74.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-rclone-2026-59732</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1125 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1125</link>
      <description>certfr-2026-avi-1125</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1125</guid>
    </item>
    <item>
      <title>EUVD-2026-339155</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-339155</link>
      <description>EUVD-2026-339155</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-339155</guid>
    </item>
    <item>
      <title>fkie_cve-2026-59732</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59732</link>
      <description>&lt;p&gt;Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone archive extract can write extracted files outside the user-selected destination prefix when extracting a crafted archive containing parent path components such as ../, allowing creation or overwrite of sibling objects in the same bucket or path scope. This issue is fixed in version 1.74.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone archive extract can write extracted files outside the user-selected destination prefix when extracting a crafted archive containing parent path components such as ../, allowing creation or overwrite of sibling objects in the same bucket or path scope. This issue is fixed in version 1.74.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-59732</guid>
    </item>
    <item>
      <title>GHSA-4vr5-p2gc-h23p — rclone archive extract allows S3 destination prefix escape via crafted archive paths</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4vr5-p2gc-h23p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/rclone/rclone&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`rclone archive extract` can write extracted files outside the user-selected destination prefix when extracting a crafted archive. A malicious archive entry containing parent path components such as `../` can escape the requested extraction prefix and create or overwrite sibling objects in the same bucket/path scope.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The affected code path is in `cmd/archive/extract/extract.go`.&lt;/p&gt;
&lt;p&gt;In `ArchiveExtract()`, the archive entry path is taken from `f.NameInArchive`. The code strips only a leading `./` prefix and then joins the archive entry path with the destination directory:&lt;/p&gt;
&lt;p&gt;```go
remote := f.NameInArchive
remote = strings.TrimPrefix(remote, &amp;#34;./&amp;#34;)
if dstDir != &amp;#34;&amp;#34; {
    remote = path.Join(dstDir, remote)
}
_, err = operations.Rcat(ctx, dst, remote, fin, f.ModTime(), nil)
```&lt;/p&gt;
&lt;p&gt;Parent path components such as `../` are not rejected before `path.Join()` is used.&lt;/p&gt;
&lt;p&gt;When the destination is an S3-style remote such as:&lt;/p&gt;
&lt;p&gt;```text
:s3:bucket/safe/prefix
```&lt;/p&gt;
&lt;p&gt;rclone creates the destination filesystem rooted at `bucket/safe` and treats `prefix` as the destination directory. If the archive contains an entry named:&lt;/p&gt;
&lt;p&gt;```text
../escaped-from-prefix.txt
```&lt;/p&gt;
&lt;p&gt;then `path.Join(&amp;#34;prefix&amp;#34;, &amp;#34;../escaped-from-prefix.txt&amp;#34;)` resolves to:&lt;/p&gt;
&lt;p&gt;```text
escaped-from-prefix.txt
```&lt;/p&gt;
&lt;p&gt;As a result, the S3 backend uploads the object to:&lt;/p&gt;
&lt;p&gt;```text
bucket/safe/escaped-from-prefix.txt
```&lt;/p&gt;
&lt;p&gt;instead of the expected destination:&lt;/p&gt;
&lt;p&gt;```text
bucket/safe/prefix/escaped-from-prefix.txt
```&lt;/p&gt;
&lt;p&gt;This allows an att…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/rclone/rclone&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`rclone archive extract` can write extracted files outside the user-selected destination prefix when extracting a crafted archive. A malicious archive entry containing parent path components such as `../` can escape the requested extraction prefix and create or overwrite sibling objects in the same bucket/path scope.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The affected code path is in `cmd/archive/extract/extract.go`.&lt;/p&gt;
&lt;p&gt;In `ArchiveExtract()`, the archive entry path is taken from `f.NameInArchive`. The code strips only a leading `./` prefix and then joins the archive entry path with the destination directory:&lt;/p&gt;
&lt;p&gt;```go
remote := f.NameInArchive
remote = strings.TrimPrefix(remote, &amp;#34;./&amp;#34;)
if dstDir != &amp;#34;&amp;#34; {
    remote = path.Join(dstDir, remote)
}
_, err = operations.Rcat(ctx, dst, remote, fin, f.ModTime(), nil)
```&lt;/p&gt;
&lt;p&gt;Parent path components such as `../` are not rejected before `path.Join()` is used.&lt;/p&gt;
&lt;p&gt;When the destination is an S3-style remote such as:&lt;/p&gt;
&lt;p&gt;```text
:s3:bucket/safe/prefix
```&lt;/p&gt;
&lt;p&gt;rclone creates the destination filesystem rooted at `bucket/safe` and treats `prefix` as the destination directory. If the archive contains an entry named:&lt;/p&gt;
&lt;p&gt;```text
../escaped-from-prefix.txt
```&lt;/p&gt;
&lt;p&gt;then `path.Join(&amp;#34;prefix&amp;#34;, &amp;#34;../escaped-from-prefix.txt&amp;#34;)` resolves to:&lt;/p&gt;
&lt;p&gt;```text
escaped-from-prefix.txt
```&lt;/p&gt;
&lt;p&gt;As a result, the S3 backend uploads the object to:&lt;/p&gt;
&lt;p&gt;```text
bucket/safe/escaped-from-prefix.txt
```&lt;/p&gt;
&lt;p&gt;instead of the expected destination:&lt;/p&gt;
&lt;p&gt;```text
bucket/safe/prefix/escaped-from-prefix.txt
```&lt;/p&gt;
&lt;p&gt;This allows an att…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4vr5-p2gc-h23p</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11241-1 — rclone-1.74.4-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11241-1</link>
      <description>&lt;p&gt;rclone-1.74.4-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rclone-1.74.4-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11241-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-59732</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59732</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: rclone, Ubuntu:Pro:20.04:LTS: rclone, Ubuntu:Pro:22.04:LTS: rclone, Ubuntu:Pro:24.04:LTS: rclone, Ubuntu:Pro:26.04:LTS: rclone&lt;/p&gt;
&lt;p&gt;Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone archive extract can write extracted files outside the user-selected destination prefix when extracting a crafted archive containing parent path components such as ../, allowing creation or overwrite of sibling objects in the same bucket or path scope. This issue is fixed in version 1.74.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: rclone, Ubuntu:Pro:20.04:LTS: rclone, Ubuntu:Pro:22.04:LTS: rclone, Ubuntu:Pro:24.04:LTS: rclone, Ubuntu:Pro:26.04:LTS: rclone&lt;/p&gt;
&lt;p&gt;Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone archive extract can write extracted files outside the user-selected destination prefix when extracting a crafted archive containing parent path components such as ../, allowing creation or overwrite of sibling objects in the same bucket or path scope. This issue is fixed in version 1.74.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59732</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2266 — rclone: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2266</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in rclone ausnutzen, um beliebige Dateien zu lesen und zu schreiben, sowie Informationen offenzulegen und Sicherheitsmechanismen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in rclone ausnutzen, um beliebige Dateien zu lesen und zu schreiben, sowie Informationen offenzulegen und Sicherheitsmechanismen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2266</guid>
    </item>
  </channel>
</rss>
