CVE-2026-71312 | Rclone up to 1.74.x sftp backend/sftp/sftp.go quoteOrEscapeShellPath os command injection
A vulnerability categorized as critical has been discovered in Rclone up to 1.74.x. Affected by this vulnerability is the function quoteOrEscapeShellPath of the file backend/sftp/sftp.go of the component sftp. Such manipulation leads to os command injection.
This vulnerability is listed as CVE-2026-71312. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More