UNKNOWN Go
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination in github.com/rclone/rclone
GO-2026-6459 · BIT-rclone-2026-88016 · CVE-2026-88016 · GHSA-f8g7-2xjc-7mfh
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination in github.com/rclone/rclone
References
- ADVISORY https://github.com/rclone/rclone/security/advisories/GHSA-f8g7-2xjc-7mfh
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-88016
- FIX https://github.com/rclone/rclone/commit/17b0c03338a857bcb0a68d2d4c82ddbdec3f7893
- FIX https://github.com/rclone/rclone/commit/a7ab39d3d1958afa1446982c1dc4e4a73a887e3e
- WEB https://github.com/rclone/rclone/releases/tag/v1.75.1
Ready to move
Start Securing
Free, no credit card | First findings in minutes