mirror of
https://github.com/rclone/rclone.git
synced 2026-09-23 22:36:00 -04:00
A request path beginning with "../" escaped the path the server was started on, letting a client list, read, create, overwrite and delete objects outside it. The check added for CVE-2026-59733 rejected non-canonical paths by comparing them with path.Clean, but path.Clean cannot resolve leading ".." elements in a relative path so it leaves them in place and the comparison comes out equal. Only interior traversal such as "a/../../x" was rejected. Whether a path then escaped depended on the backend: those which join the root with the remote before encoding it - webdav, ftp, sftp, http and memory - resolved the ".." away, while local and s3 encode the dot elements first and were unaffected. A bare "." was accepted for the same reason, which on bucket backends addresses the served directory's own key. Validate with io/fs.ValidPath instead, which rejects ".", ".." and empty elements wherever they appear. The empty path stays valid as the root of the API, and "." is excluded explicitly because ValidPath accepts it as the root of an FS.