CVE-2026-71312 | Rclone up to 1.74.x sftp backend/sftp/sftp.go quoteOrEscapeShellPath os command injection

SecurityVulns

A vulnerability categorized as critical has been discovered in Rclone up to 1.74.x. Affected by this vulnerability is the function quoteOrEscapeShellPath of the file backend/sftp/sftp.go of the component sftp. Such manipulation leads to os command injection.

This vulnerability is listed as CVE-2026-71312. The attack may be performed from remote. There is no available exploit.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More