CVE-2026-88016 | Rclone up to 1.75.0 Local MkdirMetadata/writeMetadataToFile/setTimes symlink

SecurityVulns

A vulnerability categorized as problematic has been discovered in Rclone up to 1.75.0. The affected element is the function MkdirMetadata/writeMetadataToFile/setTimes of the component Local. The manipulation results in symlink following.

This vulnerability is cataloged as CVE-2026-88016. The attack may be launched remotely. There is no exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More