Database/Control plane, storage & DevOps
rclone (serve s3): Path traversal in rclone's S3 gateway lets a caller read and overwrite files above the served root.
Impact
Path traversal in rclone's S3 gateway lets a caller read and overwrite files above the served root. Sites use rclone serve s3 to put an S3 front end on a scratch or dataset directory for training jobs; this turns that gateway into arbitrary read/write on the host filesystem outside the intended prefix.
Who can reach it
Any client that can reach the rclone serve s3 endpoint, with no authentication required in the advisory's rating.
What to do
Upgrade rclone to the fixed release and restart the serve process. Until then, run rclone serve s3 as an unprivileged user in a container or with a bind-mounted root so traversal cannot escape into anything that matters. No CVE ID has been assigned; track it by the GHSA.
References
Related entries
- KubeEdge CloudHub (viaduct packer, pkg/viaduct/pkg/packer): ONE COMPROMISED EDGE NODE TAKES DOWN CLOUD-EDGENCVD-2026-053-kubeedge-cloudhub-viaduct-packer · KubeEdge CloudHub (viaduct packer, pkg/viaduct/pkg/packer)Medium
- GitLab CE/EE: pipeline creation race lets a developer act in the context of another user's merge request commitCVE-2024-11222 · GitLab CE/EE (pipeline creation race condition)Medium
- GitLab CE/EE: authenticated user can obtain higher-privileged users' credentials and act as themCVE-2024-9183 · GitLab CE/EE (credential exposure to lower-privileged users)Medium
- Ansible Automation Platform images: group-writable /etc/passwd lets a container user become root in-containerCVE-2025-57847 · Red Hat Ansible Automation Platform container images (/etc/passwd permissions)Medium
- galaxy_ng: namespace avatar URL is fetched unchecked, giving SSRF into internal and metadata endpointsCVE-2026-79717 · galaxy_ng (Ansible Galaxy / Automation Hub server, namespace avatar fetch worker)Medium
- AWX bulk job launch: read-level permission on an instance group is enough to run jobs on itCVE-2026-84470 · Ansible Automation Platform automation-controller (AWX) Bulk Job Launch APIMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.