A high-severity vulnerability tracked as CVE-2026-71312 allows command injection in rclone versions prior to 1.75.0 when the tool interacts with SFTP servers running Windows PowerShell. The flaw stems from improper escaping in rclone's path-handling logic: it escaped only ASCII single quotes, while PowerShell also accepts several Unicode “smart quote” characters as valid string delimiters. A malicious filename on an attacker-controlled or untrusted SFTP path can therefore break out of the intended quoted string and inject arbitrary PowerShell commands.
The issue affects server-side hashing and related operations including rclone hash, rclone check, and rclone sync, potentially executing code as the victim SSH account on the remote SFTP server. Public reporting classifies the bug as CWE-78 OS command injection and lists it as remotely exploitable, with a CVSS v3.1 vector of AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H. rclone addressed the vulnerability in 1.75.0 by adding escaping for multiple Unicode smart-quote characters, and users are advised to upgrade and avoid server-side hashing against untrusted SFTP paths.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
On August 5, 2026, CVE-2026-71312 was published describing a high-severity OS command injection issue in rclone versions prior to 1.75.0. The flaw allows attacker-controlled SFTP filenames containing PowerShell smart quotes to break out of quoted paths and execute commands on remote Windows hosts when server-side hashing is invoked.
rclone addressed a command injection flaw in its SFTP backend in version 1.75.0 by escaping Unicode smart-quote characters in PowerShell path handling. The fix is referenced to GitHub commit e122fba1a57641b63a580aa26c026903a84e2e88.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvereports.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.