Database/Control plane, storage & DevOps
rclone (serve restic): Path validation in serve restic is incomplete, so an authenticated caller escapes the configured
Impact
Path validation in serve restic is incomplete, so an authenticated caller escapes the configured backend root and reaches data outside the served subtree. On a shared backup or artifact endpoint that is one tenant reading and writing another's files.
Who can reach it
Any authenticated user of an rclone serve restic endpoint.
What to do
Upgrade rclone to the release in GHSA-45pq-889g-fcgh and restart the serve process. Check for reads and writes outside each user's expected prefix, and scope the underlying storage credential to the served subtree so an escape at the rclone layer still hits a storage-side denial.
References
Related entries
- LibreNMS: device hostname is concatenated into shell commands in libvirt discovery, giving RCECVE-2026-84194 · LibreNMS libvirt VM discovery (VminfoLibvirt.php)High
- VMware Aria Automation (SQL injection): An authenticated user injects SQL and performs unauthorized read/writeCVE-2024-22280 · VMware Aria Automation (SQL injection)High
- Juniper Security Director Policy Enforcer: unauthenticated attacker can replace vSRX images pushed to VMware NSXCVE-2025-11198 · Juniper Security Director Policy Enforcer (vSRX image upload)High
- VMware Aria Operations for Logs (credential disclosure): A View Only Admin reads the credentials of other VMwareCVE-2025-22218 · VMware Aria Operations for Logs (credential disclosure)High
- VMware vCenter (SMTP header injection via scheduled tasks): A non-administrative user with scheduled-task permissionsCVE-2025-41250 · VMware vCenter (SMTP header injection via scheduled tasks)High
- AMD NBIO register lock bits - System Management Network access: NBIO registers that should be locked after boot areCVE-2025-61972 · AMD NBIO register lock bits - System Management Network accessHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.