CVE-2026-41179
The operations/fsinfo remote control (RC) endpoint in rclone was registered without requiring authentication. This allowed unauthenticated callers to instantiate arbitrary backends via inline backend definitions, which could lead to local command execution if the backend configuration allows it (e.g., via bearertokencommand in webdav or ssh in sftp).
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/rclone/rclone/security/advisories/GHSA-jfwf-28xr-xw6q, https://github.com/rclone/rclone/commit/9e3e68d00c3ecf475a1432fc206400cfb4df7e3f, https://github.com/rclone/rclone/releases/tag/v1.73.5