A high-severity vulnerability in the croc end-to-end encrypted file transfer tool allows a malicious sender to delete arbitrary files on a recipient system by sending a file named croc-marked-files.txt. Affected versions are 10.0.13 through 11.0.2. The bug stems from croc treating that received filename as its internal cleanup list and passing attacker-controlled entries directly to file-deletion logic without validating absolute paths or ../ traversal sequences, enabling removal of writable files and empty directories outside the intended transfer location.
Researchers said the flaw can be chained into remote code execution when a victim runs croc from their home directory: an attacker can first delete a shell initialization file such as ~/.bashrc and then send a malicious replacement that executes on the next shell start. The risk is higher when croc is used with --yes, which can silently accept both transfers. The issue was reported on 2026-08-10, fixed the same day in version 11.0.3 via commit c0d51f0 and PR #1232, which moved cleanup tracking into memory and restricted deletions to local paths; no CVE had been assigned at disclosure.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The vulnerability was publicly disclosed on oss-sec and in a GitHub gist, describing arbitrary file deletion in croc versions 10.0.13 through 11.0.2 and an RCE chain via replacement of shell init files such as .bashrc. The disclosure noted the issue had no CVE or formal security advisory and that version 11.0.3 contained the fix.
A security-related fix was merged into the croc main branch through commit c0d51f0 and PR #1232. The patch changed cleanup handling to keep marked files in memory and reject non-local paths, and bumped the version from 11.0.2 to 11.0.3.
Anas Souiri reported a vulnerability in croc that lets a malicious sender trigger arbitrary file deletion on the receiving host via a transferred "croc-marked-files.txt" file. The oss-sec disclosure states the issue was reported through GitHub Security Advisory and email on the same day it was fixed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourcegist.github.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.