What is CVE-2026-71312?
In rclone versions prior to 1.75.0, when interpolating remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, the quoteOrEscapeShellPath function only escapes ASCII apostrophe, potentially allowing command injection via PowerShell. This vulnerability primarily affects users utilizing the SFTP backend. Users should upgrade to rclone version 1.75.0 or later.
Azərbaycanca: rclone-un 1.75.0 versiyasından əvvəlki versiyalarında, backend/sftp/sftp.go faylında SFTP yolları PowerShell hash əmrlərinə interpolasiya edilərkən, quoteOrEscapeShellPath funksiyası yalnız ASCII apostrof simvolunu qoruyur, bu da PowerShell vasitəsilə əmr inyeksiyasına səbəb ola bilər. Bu zəiflik əsasən SFTP backendindən istifadə edən rclone istifadəçilərinə təsir edir. İstifadəçilər rclone-u 1.75.0 və ya daha yeni versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
Which versions of rclone are affected by CVE-2026-71312?
This vulnerability affects rclone versions prior to 1.75.0.
What should users do to mitigate CVE-2026-71312?
Users should upgrade to rclone version 1.75.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.