<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 05:57:51 +0000</lastBuildDate>
    <item>
      <title>BIT-rclone-2026-71312 — rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution</title>
      <link>https://cve.radiocsirt.org/vuln/bit-rclone-2026-71312</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: rclone&lt;/p&gt;
&lt;p&gt;rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscapeShellPath escapes only ASCII apostrophe even though PowerShell treats U+2018, U+2019, U+201A, and U+201B as single-quote delimiters, allowing an attacker-controlled filename to terminate the intended path literal and append PowerShell statements that execute as the victim SSH account when server-side hashing is invoked. This issue is fixed in v1.75.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: rclone&lt;/p&gt;
&lt;p&gt;rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscapeShellPath escapes only ASCII apostrophe even though PowerShell treats U+2018, U+2019, U+201A, and U+201B as single-quote delimiters, allowing an attacker-controlled filename to terminate the intended path literal and append PowerShell statements that execute as the victim SSH account when server-side hashing is invoked. This issue is fixed in v1.75.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-rclone-2026-71312</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1125 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1125</link>
      <description>certfr-2026-avi-1125</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1125</guid>
    </item>
    <item>
      <title>EUVD-2026-349195</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-349195</link>
      <description>EUVD-2026-349195</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-349195</guid>
    </item>
    <item>
      <title>fkie_cve-2026-71312</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-71312</link>
      <description>&lt;p&gt;rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscapeShellPath escapes only ASCII apostrophe even though PowerShell treats U+2018, U+2019, U+201A, and U+201B as single-quote delimiters, allowing an attacker-controlled filename to terminate the intended path literal and append PowerShell statements that execute as the victim SSH account when server-side hashing is invoked. This issue is fixed in v1.75.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscapeShellPath escapes only ASCII apostrophe even though PowerShell treats U+2018, U+2019, U+201A, and U+201B as single-quote delimiters, allowing an attacker-controlled filename to terminate the intended path literal and append PowerShell statements that execute as the victim SSH account when server-side hashing is invoked. This issue is fixed in v1.75.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-71312</guid>
    </item>
    <item>
      <title>GHSA-2m8m-jhrm-w6j2 — rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2m8m-jhrm-w6j2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/rclone/rclone&lt;/p&gt;
&lt;p&gt;## 1. Summary&lt;/p&gt;
&lt;p&gt;rclone interpolates remote SFTP paths into PowerShell hash commands. Its quoting helper escapes only ASCII apostrophe, although PowerShell accepts four Unicode smart quotes as single-quote delimiters. An attacker-controlled filename can therefore terminate the intended path literal and append PowerShell statements executed as the victim&amp;#39;s SSH account.&lt;/p&gt;
&lt;p&gt;## 2. Affected Assets &amp;amp; Attack Surface&lt;/p&gt;
&lt;p&gt;- Audited commit: `a0c09f1381ae93e2a9a33c529d170186c61ad058`
- Backend: `backend/sftp`
- Relevant code:
  - `backend/sftp/sftp.go:1802-1812` — PowerShell hash commands
  - `backend/sftp/sftp.go:1663-1699` — `Fs.run`
  - `backend/sftp/sftp.go:1988-2067` — `Object.Hash`
  - `backend/sftp/sftp.go:2071-2090` — `quoteOrEscapeShellPath`
- Exposed input: remote filename controlled by an SFTP collaborator, upstream storage source, or other party able to create or rename files.
- Required execution context: PowerShell as the SSH command shell, SSH exec enabled, and server-side hashing invoked.&lt;/p&gt;
&lt;p&gt;## 3. Technical Root Cause Analysis&lt;/p&gt;
&lt;p&gt;For PowerShell, `quoteOrEscapeShellPath` wraps a path in ASCII apostrophes and doubles only `U+0027`:&lt;/p&gt;
&lt;p&gt;```go
return &amp;#34;&amp;#39;&amp;#34; + strings.ReplaceAll(shellPath, &amp;#34;&amp;#39;&amp;#34;, &amp;#34;&amp;#39;&amp;#39;&amp;#34;) + &amp;#34;&amp;#39;&amp;#34;, nil
```&lt;/p&gt;
&lt;p&gt;Windows PowerShell also treats `U+2018`, `U+2019`, `U+201A`, and `U+201B` as single-quote delimiters. Those characters pass through the rclone encoder and can close the quoted path. The completed string is sent as shell source through an SSH exec request.&lt;/p&gt;
&lt;p&gt;The security boundary f…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/rclone/rclone&lt;/p&gt;
&lt;p&gt;## 1. Summary&lt;/p&gt;
&lt;p&gt;rclone interpolates remote SFTP paths into PowerShell hash commands. Its quoting helper escapes only ASCII apostrophe, although PowerShell accepts four Unicode smart quotes as single-quote delimiters. An attacker-controlled filename can therefore terminate the intended path literal and append PowerShell statements executed as the victim&amp;#39;s SSH account.&lt;/p&gt;
&lt;p&gt;## 2. Affected Assets &amp;amp; Attack Surface&lt;/p&gt;
&lt;p&gt;- Audited commit: `a0c09f1381ae93e2a9a33c529d170186c61ad058`
- Backend: `backend/sftp`
- Relevant code:
  - `backend/sftp/sftp.go:1802-1812` — PowerShell hash commands
  - `backend/sftp/sftp.go:1663-1699` — `Fs.run`
  - `backend/sftp/sftp.go:1988-2067` — `Object.Hash`
  - `backend/sftp/sftp.go:2071-2090` — `quoteOrEscapeShellPath`
- Exposed input: remote filename controlled by an SFTP collaborator, upstream storage source, or other party able to create or rename files.
- Required execution context: PowerShell as the SSH command shell, SSH exec enabled, and server-side hashing invoked.&lt;/p&gt;
&lt;p&gt;## 3. Technical Root Cause Analysis&lt;/p&gt;
&lt;p&gt;For PowerShell, `quoteOrEscapeShellPath` wraps a path in ASCII apostrophes and doubles only `U+0027`:&lt;/p&gt;
&lt;p&gt;```go
return &amp;#34;&amp;#39;&amp;#34; + strings.ReplaceAll(shellPath, &amp;#34;&amp;#39;&amp;#34;, &amp;#34;&amp;#39;&amp;#39;&amp;#34;) + &amp;#34;&amp;#39;&amp;#34;, nil
```&lt;/p&gt;
&lt;p&gt;Windows PowerShell also treats `U+2018`, `U+2019`, `U+201A`, and `U+201B` as single-quote delimiters. Those characters pass through the rclone encoder and can close the quoted path. The completed string is sent as shell source through an SSH exec request.&lt;/p&gt;
&lt;p&gt;The security boundary f…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2m8m-jhrm-w6j2</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-71312</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-71312</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: rclone, Ubuntu:Pro:20.04:LTS: rclone, Ubuntu:Pro:22.04:LTS: rclone, Ubuntu:Pro:24.04:LTS: rclone, Ubuntu:Pro:26.04:LTS: rclone&lt;/p&gt;
&lt;p&gt;rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscapeShellPath escapes only ASCII apostrophe even though PowerShell treats U+2018, U+2019, U+201A, and U+201B as single-quote delimiters, allowing an attacker-controlled filename to terminate the intended path literal and append PowerShell statements that execute as the victim SSH account when server-side hashing is invoked. This issue is fixed in v1.75.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: rclone, Ubuntu:Pro:20.04:LTS: rclone, Ubuntu:Pro:22.04:LTS: rclone, Ubuntu:Pro:24.04:LTS: rclone, Ubuntu:Pro:26.04:LTS: rclone&lt;/p&gt;
&lt;p&gt;rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscapeShellPath escapes only ASCII apostrophe even though PowerShell treats U+2018, U+2019, U+201A, and U+201B as single-quote delimiters, allowing an attacker-controlled filename to terminate the intended path literal and append PowerShell statements that execute as the victim SSH account when server-side hashing is invoked. This issue is fixed in v1.75.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-71312</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2679 — rclone: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2679</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in rclone ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in rclone ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2679</guid>
    </item>
  </channel>
</rss>
