GHSA-c476-6w5q-jw77: rclone: FTP cross-session auth-proxy backend confusion
HIGHHigh-risk vulnerability — CVSS 7.3
## Summary The FTP auth-proxy driver stores one obscured password per username in a server-wide map. It does not bind the credential or returned VFS to the authenticated FTP session. If two accepted credentials use the same username but resolve to different proxy backends, the later login overwrites the map entry. Subsequent operations on the first, still-authenticated session are re-authorized with the later session's password and execute against the later session's backend. This is not exploitable in every auth-proxy deployment. …
CVE · detail
- CVE-2026-88017nvd ↗EPSS 0.23%
Early access
Get the next one first.
Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.
bot-protected