CVE-2026-71311Disclosure

LOWCVSS 6.4 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, a valid but nondefault FTP filename encoding in backend/ftp/ftp.go can restore raw CR/LF immediately before an attacker-controlled path is interpolated into the line-oriented FTP control channel, and github.com/jlaffaye/ftp formats the argument through textproto.Conn.Cmd without rejecting CR or LF, allowing a filename such as victim CRLF DELE other-secret CRLF NOOP to inject an independent authenticated FTP command when the victim copies or syncs to a more-privileged FTP destination. This issue is fixed in 1.75.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-93

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-06: 2Technical Details · 2026-08-06: 208-06
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-71311 rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, a valid but nondefault FTP filename enc… https://www.cve.org/CVERecord?id=CVE-2026-71311 ----- Traducción: CVE-2026-71311 rcl… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑71311, describing a vulnerability in rclone affecting FTP filenames prior to version 1.75.0, but provides no PoC, exploit, patch, or active exploitation details.

    0000050
    97 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-71311 rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, a valid but nondefault FTP filename enc… https://www.cve.org/CVERecord?id=CVE-2026-71311

    Post summary

    The excerpt provides a brief CVE record link and a technical note on an FTP filename encoding flaw in rclone version 1.75.0 or earlier, but offers no PoC, exploit, or patch details.

    00000706
    57.9K followersView on X

Explore more