CVE-2026-79777
5.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| rclone | rclone | 0 < 1.75.0 | affected |
| rclone | rclone | 1.75.0 | unaffected |
Weaknesses
- CWE-209: Generation of Error Message Containing Sensitive Information
References
- https://github.com/rclone/rclone/security/advisories/GHSA-gwfq-86j8-7qhv
- https://www.vulncheck.com/advisories/rclone-before-information-disclosure-via-rc-api
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.