Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
GHSA-4vr5-p2gc-h23p
Summary
rclone archive extract can write extracted files outside the user-selected destination prefix when extracting a crafted archive. A malicious archive entry containing parent path components such as ../ can escape the requested extraction prefix and create or overwrite sibling objects in the same bucket/path scope.
Details
The affected code path is in cmd/archive/extract/extract.go.
In ArchiveExtract(), the archive entry path is taken from f.NameInArchive. The code strips only a leading ./ prefix and then joins the archive entry path with the destination directory:
remote := f.NameInArchive
remote = strings.TrimPrefix(remote, "./")
if dstDir != "" {
remote = path.Join(dstDir, remote)
}
_, err = operations.Rcat(ctx, dst, remote, fin, f.ModTime(), nil)
Parent path components such as ../ are not rejected before path.Join() is used.
When the destination is an S3-style remote such as:
:s3:bucket/safe/prefix
rclone creates the destination filesystem rooted at bucket/safe and treats prefix as the destination directory. If the archive contains an entry named:
../escaped-from-prefix.txt
then path.Join("prefix", "../escaped-from-prefix.txt") resolves to:
escaped-from-prefix.txt
As a result, the S3 backend uploads the object to:
bucket/safe/escaped-from-prefix.txt
instead of the expected destination:
bucket/safe/prefix/escaped-from-prefix.txt
This allows an attacker-controlled archive to escape the selected extraction prefix on object-storage remotes.
PoC
Test environment:
- Windows 11
- rclone v1.74.3 official Windows amd64 binary
- Local fake S3 HTTP endpoint
- Crafted ZIP archive containing
../escaped-from-prefix.txt
Steps to reproduce:https://drive.google.com/file/d/1P_cLKFgiWSVSATB8500yP28jdzwt9FAt/view?usp=sharing
-
Extract the attached PoC ZIP.
-
Run the PoC script:
powershell -ExecutionPolicy Bypass -File .\run-poc.ps1 -RcloneExe "C:\path\to\rclone.exe"
- The PoC creates a ZIP archive containing this entry:
../escaped-from-prefix.txt
- The PoC starts a local fake S3 endpoint and runs rclone with an S3-style destination prefix:
rclone archive extract malicious.zip :s3:bucket/safe/prefix
- Observe the fake S3 request log.
Expected safe behavior:
PUT /bucket/safe/prefix/escaped-from-prefix.txt
Observed behavior:
PUT /bucket/safe/escaped-from-prefix.txt?x-id=PutObject
This shows that the archive entry escaped the requested safe/prefix destination and was written under safe/ instead.
The PoC package includes:
run-poc.ps1fake-s3-server.pyREADME.mdreport-draft.md- captured proof logs
Impact
An attacker who supplies an archive that a victim extracts with rclone archive extract can cause extracted files to be written outside the destination prefix selected by the victim when the destination is an S3-style object storage remote.
Depending on the victim's configured remote credentials and bucket permissions, this may allow creation or overwrite of sibling objects outside the intended extraction directory/prefix.
This does not require compromising the S3 service itself. The attack relies on the victim extracting an attacker-controlled archive with rclone into an object-storage prefix.
The vulnerability requires local access to the device to be exploited. It is easy for an attacker to exploit this vulnerability. An attacker does not need any special privileges or access rights. The attacker needs the user to perform some action, like clicking a link. The vulnerability can affect other systems as well, not just the initial system. There is a low impact on the integrity of the data. There is a low impact on the availability of the system.
Exploitation attempts have been detected. Elevated vigilance and prompt remediation are advised.
The exploit probability is very low. The vulnerability is unlikely to be exploited in the next 30 days.
We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.
Browse More
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard