github.com/ncw/rclone
"rsync for cloud storage" - Google Drive, S3, Dropbox, Backblaze B2, One Drive, Swift, Hubic, Wasabi, Google Cloud Storage, Azure Blob, Azure Files, Yandex Files
Activity
- Latest release
- 1w ago
- Total releases
- 57
- Cadence
- ~32 days
- Last 12 months
- 16
Reach
- Stars
- 59.7k
Details
- First release
- Sep 07, 2018
| Version | Released | |
|---|---|---|
v1.75.1
patch
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.75.1
patch
Dependencies (110)
+ 102 more |
|
v1.75.0
minor
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.75.0
minor
Dependencies (110)
+ 102 more |
|
v1.74.4
patch
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.74.4
patch
Dependencies (109)
+ 101 more |
|
v1.74.3
patch
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.74.3
patch
Dependencies (109)
+ 101 more |
|
v1.74.2
patch
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.74.2
patch
Dependencies (109)
+ 101 more |
|
v1.74.1
minor
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.74.1
minor
Dependencies (109)
+ 101 more |
|
v1.74.0
minor
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.74.0
minor
Dependencies (109)
+ 101 more |
|
v1.73.5
patch
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.73.5
patch
Dependencies (106)
+ 98 more |
|
v1.73.4
patch
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.73.4
patch
Dependencies (106)
+ 98 more |
|
v1.73.3
patch
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.73.3
patch
Dependencies (106)
+ 98 more |
|
v1.73.2
patch
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.73.2
patch
Dependencies (106)
+ 98 more |
|
v1.73.1
minor
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.73.1
minor
Dependencies (106)
+ 98 more |
|
v1.73.0
minor
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.73.0
minor
Dependencies (106)
+ 98 more |
|
v1.72.1
patch
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.72.1
patch
Dependencies (102)
+ 94 more |
|
v1.72.0
minor
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.72.0
minor
Dependencies (102)
+ 94 more |
|
v1.71.2
patch
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.71.2
patch
Dependencies (97)
+ 89 more |
|
v1.71.1
patch
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.71.1
patch
Dependencies (97)
+ 89 more |
|
v1.71.0
minor
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.71.0
minor
Dependencies (97)
+ 89 more |
|
v1.70.3-sb.0
pre
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.70.3-sb.0
pre
Dependencies (94)
+ 86 more |
|
v1.70.3
patch
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.70.3
patch
Dependencies (94)
+ 86 more |
|
v1.70.2
patch
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.70.2
patch
Dependencies (94)
+ 86 more |
|
v1.70.0
minor
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.70.0
minor
Dependencies (94)
+ 86 more |
|
v1.69.0
minor
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.69.0
minor
Dependencies (93)
+ 85 more |
|
v1.68.2
patch
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.68.2
patch
Dependencies (92)
+ 84 more |
|
v1.68.0
minor
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.68.0
minor
Dependencies (92)
+ 84 more |
|
v1.65.2
patch
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.65.2
patch
Dependencies (84)
+ 76 more |
|
v1.65.1
minor
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.65.1
minor
Dependencies (84)
+ 76 more |
|
v1.64.0
minor
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.64.0
minor
Dependencies (77)
+ 69 more |
|
v1.63.1
minor
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.63.1
minor
Dependencies (75)
+ 67 more |
|
v1.62.0
minor
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.62.0
minor
Dependencies (74)
+ 66 more |
|
v1.61.1
minor
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.61.1
minor
Dependencies (74)
+ 66 more |
|
v1.60.1
patch
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.60.1
patch
Dependencies (72)
+ 64 more |
|
v1.60.0
minor
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.60.0
minor
Dependencies (72)
+ 64 more |
|
v1.59.2
patch
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.59.2
patch
Dependencies (70)
+ 62 more |
|
v1.59.1
patch
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.59.1
patch
Dependencies (70)
+ 62 more |
|
v1.59.0
minor
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.59.0
minor
Dependencies (70)
+ 62 more |
|
v1.58.1
patch
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.58.1
patch
Dependencies (66)
+ 58 more |
|
v1.58.0
minor
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.58.0
minor
Dependencies (66)
+ 58 more |
|
v1.57.0
minor
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.57.0
minor
Dependencies (65)
+ 57 more |
|
v1.55.1
patch
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.55.1
patch
Dependencies (62)
+ 54 more |
|
v1.55.0
minor
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.55.0
minor
Dependencies (62)
+ 54 more |
|
v1.54.1
patch
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.54.1
patch
Dependencies (59)
+ 51 more |
|
v1.54.0
minor
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.54.0
minor
Dependencies (59)
+ 51 more |
|
v1.53.3
patch
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.53.3
patch
Dependencies (54)
+ 46 more |
|
v1.53.1
patch
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.53.1
patch
Dependencies (54)
+ 46 more |
|
v1.53.0
minor
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.53.0
minor
Dependencies (54)
+ 46 more |
|
v1.52.3
minor
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.52.3
minor
Dependencies (54)
+ 46 more |
|
v1.51.0
minor
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.51.0
minor
Dependencies (49)
+ 41 more |
|
v1.50.2
patch
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.50.2
patch
Dependencies (49)
+ 41 more |
|
v1.50.1
patch
2 CVEs
CVE-2026-49980
GO-2026-5596
BIT-rclone-2026-49980
GHSA-qw24-gh76-8rvv
Aug 11, 2026
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone The --rc-serve path in rclone allows unauthenticated remote instantiation, enabling unauthenticated command execution. An attacker can use inline remote backend options such as sftp ssh to run arbitrary commands as the rclone user. References
Updated Aug 14, 2026 · Source: OSV.dev
CVE-2026-41179
GO-2026-5466
BIT-rclone-2026-41179
GHSA-jfwf-28xr-xw6q
Aug 11, 2026
Unauthenticated backend instantiation in github.com/rclone/rclone The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearer_token_command in webdav or ssh in sftp). References Updated Aug 14, 2026 · Source: OSV.dev |
v1.50.1
patch
Dependencies (49)
+ 41 more |