mirror of
https://github.com/rclone/rclone.git
synced 2026-09-16 08:27:21 -04:00
The local backend built every OS path by joining the root with the source name converted through the configured encoding, so the encoding was the only thing keeping a name from turning into path syntax. With an encoding which omits Dot (Slash, None, Raw) rclone's standard ".." decodes back to a real "..", and with an encoding which omits BackSlash a name like "..\file" becomes a native path on Windows. filepath.Join then resolved those out of the destination the user chose, so a source object called "../marker.txt" - an s3 key of "tenant/../marker.txt" listed with the remote rooted at "tenant", say - created or overwrote a file outside it. localPath now joins the name to the root and checks with filepath.Rel that the result is still inside it. localPath is the only place the root is joined to a name, so threading the error through newObject and newDirectory covers every operation. Default configurations were not affected, as encoder.OS includes Dot on all platforms and BackSlash on Windows. Fixes GHSA-7p4m-qxvv-g567