Aug 6, 2026·8 min read·94 visits
Unsanitized path extraction in rclone allows directory traversal and arbitrary file overwrite.
A path traversal vulnerability (Zip Slip variant) exists in rclone's archive extract functionality before version 1.74.4. The command fails to sanitize relative directory components in archive headers, allowing files to be written outside the target directory or cloud prefix. This issue can result in arbitrary file writes or cloud object overwrites depending on the permissions of the credentials used. Nick Craig-Wood authored the patch on June 29, 2026, which was released in version 1.74.4 on July 14, 2026. This vulnerability is assigned CVE-2026-59732 and is cataloged as GHSA-4vr5-p2gc-h23p. This report provides a detailed root cause analysis, code-level diff, and remediation steps.
The command-line tool rclone supports synchronizing, copying, and archiving files across more than 40 cloud storage providers and local filesystems. Within its feature set, the utility offers an archive extraction capability under the rclone archive extract subcommand. This function is designed to unpack standard compressed formats directly into specified remotes or local targets, handling nested structures efficiently.
Prior to version 1.74.4, the utility did not implement robust path sanitation filters on compressed archives. This omission exposed the extraction process to a well-known vulnerability class commonly referred to as path traversal or 'Zip Slip'. Under this condition, file headers within an archive can contain relative path components that manipulate the destination path during extraction.
When a user executes the extraction tool on an untrusted archive, the utility resolves the relative directory sequences. This resolution can result in writing files to locations outside the user-defined root folder or object prefix. The vulnerability resides globally in the archive processing logic, affecting both local storage backends and simulated hierarchical namespaces on object storage backends.
Security teams must evaluate the risk of this utility when deployed in automated pipelines. Many data ingestion architectures utilize rclone to process files automatically. If these pipelines ingest archives from external or unauthenticated sources, the system becomes vulnerable to directory escape and target state corruption.
The root cause of CVE-2026-59732 lies in the reliance on Go's standard library path.Join() function without prior input validation. During the extraction of archive structures, such as ZIP or TAR archives, the utility retrieves individual entry headers. Specifically, the field NameInArchive contains the relative location of the file as recorded by the archive creation utility.
In vulnerable versions of rclone, the utility attempts to clean the path by removing simple relative prefixes. This is executed using the strings.TrimPrefix(remote, "./") construct. However, this check is insufficient because it only targets leading ./ patterns and ignores parent directory traversal indicators such as ../ or backslash representations on Windows targets.
Following the prefix trimming, the code attempts to restrict the destination by joining the user-defined output path (dstDir) with the archive entry path (remote). The logic executes path.Join(dstDir, remote). Because path.Join automatically invokes path.Clean, it collapses any parent directory traversal sequences. For instance, joining a destination path of restricted_dir with an archive entry of ../escaped.txt yields escaped.txt.
This behavior is highly problematic when interacting with cloud storage systems like Amazon S3. In object storage, directories are simulated using prefix strings on flat key structures. Because the path collapses, the target key evaluates to a location outside the logical prefix directory. Consequently, rclone uploads the file directly to the broader bucket level, breaking the expected directory isolation boundary.
An inspection of the vulnerable implementation in cmd/archive/extract/extract.go highlights the flawed handling of user-controlled archive paths. The original logic retrieved the archive header name and attempted to clean it with simple string manipulation. It then combined the directory values without confirming that the final path remained subordinate to the base directory.
// Vulnerable Code Implementation in rclone < 1.74.4
remote := f.NameInArchive
// Strip leading "./" from archive paths.
remote = strings.TrimPrefix(remote, "./")
// If the entry was exactly "./" (the root dir), skip it
if remote == "" && f.IsDir() {
return nil
}
if dstDir != "" {
remote = path.Join(dstDir, remote)
}To remediate this structural flaw, the development team introduced a dedicated validation function named destPath. This helper enforces a strict validation routine on all archive member paths before any operations take place. It parses each segment of the path to identify traversal patterns and terminates processing upon discovering unsafe structures.
// Patched Code Implementation in rclone 1.74.4
func destPath(nameInArchive, dstDir string) (string, error) {
remote := strings.TrimPrefix(nameInArchive, "./")
isSeparator := func(r rune) bool { return r == '/' || r == '\\' }
// Split path into segments and check for directory traversal markers
for _, segment := range strings.FieldsFunc(remote, isSeparator) {
if segment == ".." {
return "", fmt.Errorf("refusing to extract archive entry %q with a %q path component", nameInArchive, "..")
}
}
if remote == "" {
return "", nil
}
if dstDir != "" {
remote = path.Join(dstDir, remote)
}
return remote, nil
}> [!NOTE]
> The patched logic splits paths using both forward slash / and backslash \ as separators. This ensures that Windows-specific paths are handled securely, preventing traversal attempts on environments where backslashes are resolved dynamically. The use of strings.FieldsFunc guarantees that every subdirectory token is inspected individually.
Exploitation of CVE-2026-59732 requires a local user or automated script to execute the rclone archive extract command against a maliciously structured archive. The attacker does not need direct access to the target host if they can influence the source archive files being processed by an automated ingestion pipeline. This makes the attack highly relevant for file upload endpoints and automated data-processing tasks.
An attacker begins by creating a standard compressed archive, such as a ZIP file. Because standard archiving utilities restrict the creation of paths containing parent directory segments, the attacker uses specialized scripting tools to write raw bytes directly into the archive headers. The file headers are manually adjusted to set file path values to target locations like ../target_file.txt or ../../target_file.txt.
Once the archive is prepared, the attacker induces the target system to run the extraction process. The extraction command is initiated with a specific destination folder. The following command illustrates the execution structure:
rclone archive extract malicious_payload.zip :s3:company-data-bucket/user_space/destination_folderWhen rclone processes the file named ../overwritten_config.json, the path resolver converts the target key to user_space/overwritten_config.json. The application completes the upload to this calculated key path. The file is written outside the intended destination_folder prefix, which can overwrite existing objects and alter application configuration settings within the cloud storage architecture.
The concrete security impact of CVE-2026-59732 depends on the execution environment and the permissions assigned to the rclone utility. In scenarios where rclone operates with high-privilege credentials on local filesystems, a path traversal can lead to unauthorized file writes. An attacker can write files to sensitive directories, potentially altering system configuration files or writing malicious scripts into startup folders.
In cloud storage environments, the impact is primarily centered on integrity and availability. Cloud providers utilize flat object spaces with logical directory prefixes. If the credentials assigned to rclone possess broad write permissions across an entire bucket, the utility can overwrite files in sibling directories. This bypasses folder-level logical isolation and compromises data integrity within shared storage spaces.
The vulnerability is assigned a CVSS score of 5.0 (Medium). The score reflects the requirement of user interaction, as a victim or system must trigger the extraction command. Additionally, no direct confidentiality impact is associated with the vulnerability, meaning the flaw does not facilitate direct arbitrary file read operations. However, the integrity and operational disruption risks remain significant.
The primary and most effective remediation path is to upgrade all rclone installations to version 1.74.4 or higher. This release integrates the segment-based tokenization check within the destPath helper, which successfully identifies and blocks all traversal attempts. Security teams should audit their container images and automation environments to ensure older binaries are replaced.
In environments where immediate software upgrades are not feasible, administrators must implement strict access controls. When utilizing cloud providers like Amazon S3, apply the principle of least privilege to IAM policies. Limit the scope of write actions to specific prefixes using condition keys, ensuring that even if rclone attempts to resolve a path outside the destination, the cloud provider blocks the write operation.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": ["s3:PutObject"],
"Resource": ["arn:aws:s3:::company-data-bucket/user_space/destination_folder/*"]
}
]
}Additionally, running rclone within sandboxed environments such as Docker containers with restricted volume mounts reduces local filesystem exposure. Ensure that containerized workloads run as non-root users and do not mount host root directories. This isolation prevents any path traversal on the local host from affecting critical operating system files.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L| Product | Affected Versions | Fixed Version |
|---|---|---|
rclone rclone | < 1.74.4 | 1.74.4 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-22 |
| Attack Vector | Local (AV:L) |
| CVSS Score | 5.0 (Medium) |
| EPSS Score | 0.00213 (Percentile: 11.63%) |
| Impact | Integrity and Availability (Partial) |
| Exploit Status | Proof of Concept (PoC) available |
| KEV Status | Not listed |
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVE-2026-107717 represents a critical prompt boundary bypass and chat role injection vulnerability in the Banks Python package (versions prior to 2.5.0). The library parses generated template outputs line-by-line, attempting to validate each segment as a JSON-serialized ChatMessage object without validating the source boundaries of the text. If an application integrates user input directly into a prompt template, a remote, unauthenticated attacker can supply multi-line inputs with structured JSON payloads. This input is then parsed as high-privilege system instructions or tool execution responses, completely hijacking downstream Large Language Model behavior.
Improper pathname limitation and link resolution (CWE-22 and CWE-59) in the banks library prior to version 2.5.1 allow local attackers to read or write arbitrary files via crafted symbolic links in the prompt directory registry.
Improper validation of dynamic class resolution within Hazelcast's Zero Config Compact Serialization allows unauthenticated clients to trigger reflective class instantiation. This flaw can be exploited to read arbitrary JVM heap or off-heap memory, crash cluster nodes, or achieve arbitrary code execution under specific classpath conditions. This issue is resolved in Hazelcast versions 5.4.5, 5.5.10, 5.6.1, and 5.7.0.
An authentication bypass vulnerability in NearForm's fast-jwt before version 6.3.4 allows attackers to replay expired tokens due to an error in the verifier's cache expiration logic. When caching is enabled, the cache TTL defaults to 10 minutes instead of honoring the token's exp claim if the token lacks an iat claim.
CVE-2026-61427 is a critical authentication bypass and improper input validation vulnerability within the Model Context Protocol (MCP) HTTP-stream server of PraisonAI. In versions prior to 4.6.78, the server lacks authentication by default and forwards client messages directly to Python tool handlers without input validation. When bound to non-localhost interfaces, this permits unauthenticated remote attackers to perform unauthorized administrative operations and execute tools.
CVE-2026-107387 is a high-impact uncontrolled memory allocation vulnerability in music-metadata, a widely used Node.js metadata parser. The flaw occurs in the APEv2 tag parser, where the library reads an attacker-controlled 32-bit integer indicating the tag size and immediately requests a corresponding heap buffer reservation. Because this allocation occurs before validating if the input stream actually contains those bytes, an attacker can supply a minuscule audio file to trigger large, disproportionate allocations, resulting in heap exhaustion and an uncatchable process-wide Out of Memory (OOM) crash.