Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticated GET and HEAD requests to paths of the form: /[remote:path]/object. The remote value is parsed from the URL and passed to normal backend initialization. Inline remote configuration can set backend options that execute local commands during initialization. As a result, a single unauthenticated GET or HEAD request can execute a command as the rclone process user. This vulnerability is fixed in 1.74.3.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade rclone-debuginfoUpgrade rclone | Jul 7, 2026 | Jul 7, 2026 |
| Amazon_linux_2023 | — | Upgrade rcloneUpgrade rclone-debugsourceUpgrade rclone-debuginfo | Jun 30, 2026 | Jun 24, 2026 |
| Freebsd | — | Upgrade rclone | Jun 30, 2026 | Jun 29, 2026 |
| Ubuntu | — | Upgrade rclone | Sep 21, 2026 | Sep 18, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub