rclone
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 26 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from June 27, 2018 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →rclone serve docker Path Traversal via Volume Name
rclone before 1.75.1 Path Traversal via Directory Listing Names
rclone: source object names can escape the configured root on upload
rclone: S3 multipart declared-length memory exhaustion
rclone: RC per-server auth-proxy bypass
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
rclone: FTP cross-session auth-proxy backend confusion
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
rclone local: crafted Range request against a translated symlink panics (DoS)
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
Monitor rclone in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.