CRITICAL9.8CVE-2026-49980Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix from 0
CRITICAL9.8CVE-2026-41179RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution from 0
CRITICAL9.8CVE-2026-41176Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution from 0
HIGH8.8rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
from 0
HIGH8.8rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote
from 0
HIGH7.5Use of Cryptographically Weak Pseudo-Random Number Generator in Rclone in github.com/rclone/rclone
from 0, < 1.53.3-1
HIGH7.5Use of Cryptographically Weak Pseudo-Random Number Generator in Rclone in github.com/rclone/rclone
from 0, < 1.53.3-1
MEDIUM5.9golang-go.crypto - security update
from 0, < 1.35-1+deb8u1
MEDIUM5.0rclone archive extract allows S3 destination prefix escape via crafted archive paths
from 0
—Rclone Improper Permission and Ownership Handling on Symlink Targets with --links and --metadata
from 0