Executive brief
rclone is a command-line tool for syncing files to and from cloud storage and local filesystems. When copying files with metadata preservation from an untrusted remote, an attacker can supply specially crafted file permissions that cause rclone to create setuid binaries. If rclone runs as root (common for backup and restore operations), this allows any local user to gain root access; if running as a service account, it enables privilege escalation to that account.
Technical details
The vulnerability exists in rclone's local backend metadata handling (backend/local/metadata.go, writeMetadataToFile). When applying mode metadata from the source, the code parses the mode value and passes it directly to os.Chmod() without masking special permission bits (setuid, setgid, sticky). An attacker can supply a mode value such as 40000755 (Go FileMode layout with setuid bit set) along with uid=0 to create a root-owned setuid binary with attacker-controlled content. The attack requires the victim to run rclone with the -M (metadata preservation) flag on an attacker-controlled or compromised remote. The fix masks permission bits before applying them and gates uid/gid/setuid application behind an off-by-default opt-in flag.
Affected products
- rclone rclone before 1.74.4
Timeline
- 2026-07-08: disclosed
- 2026-08-25: advisory
- 2026-08-25: patched: version 1.74.4