rclone Package Path Validation Vulnerability: Early Warning
An early warning has been issued regarding a potential vulnerability in the rclone package, versions v1.40 through v1.74.4, where incomplete path validation may allow an attacker to escape the configured path and perform unauthorized actions.
What happened
Reportedly, the rclone package does not correctly reject URL paths beginning with `../`, which appears to allow an attacker to read, create, overwrite, or delete objects outside the configured path. This vulnerability, tracked as GHSA-45PQ-889G-FCGH, is under investigation. Software engineers using affected versions of rclone are advised to assess their exposure and consider upgrading to a version after v1.74.4 to mitigate potential risks. For more detailed information, primary sources should be consulted.
How 0Day mitigates this
rclone is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.