UNKNOWNGo →
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone
Affected packages
- github.com/ncw/rclone
- github.com/rclone/rclone
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/rclone/rclone/security/advisories/GHSA-qw24-gh76-8rvv
- https://github.com/rclone/rclone/commit/48da1774f4999d1d46543308b9a7fe75585dbfc4
- https://github.com/rclone/rclone/commit/9222ed2c5a7678de7fa620214b0858311c707a29
- https://access.redhat.com/security/cve/CVE-2026-49980
- https://bugzilla.redhat.com/show_bug.cgi?id=2492478
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49980.json
Structured record: https://osv.dev/vulnerability/GO-2026-5596
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta