CVE-2026-93987 | rclone up to 1.75.0 Docker Volume Plugin volume.go newVolume Name path traversal

SecurityVulns

A vulnerability classified as problematic has been found in rclone up to 1.75.0. Affected is the function newVolume of the file cmd/serve/docker/volume.go of the component Docker Volume Plugin. The manipulation of the argument Name leads to path traversal.

This vulnerability is referenced as CVE-2026-93987. Remote exploitation of the attack is possible. No exploit is available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More