CVE-2026-41179 is an OS command injection vulnerability in Rclone versions 1.48.0 through versions before 1.73.5. The RC operations/fsinfo endpoint accepts attacker-controlled fs input but was not marked as requiring authentication. The endpoint invokes rc.GetFs(...), which supports inline backend definitions and permits an unauthenticated requester to instantiate an attacker-controlled backend. During initialization of an inline WebDAV backend, the bearer_token_command option is executed, allowing local command execution from a single RC request.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a small standalone proof-of-concept/test environment for exploiting rclone remote control command injection/RCE. Structure: (1) rce.py is the main exploit and only substantive code; it uses Python requests to POST attacker-controlled form data to the rclone RC API endpoint /operations/fsinfo. The malicious fs parameter declares a :webdav backend and injects a bearer_token_command value containing a URL-encoded bash -c command. A random uuid is added so repeated requests are re-executed. Two execution modes are implemented: a default 'dirty' mode that captures command output by piping stderr/stdout through base64 and parsing the encoded data from the JSON error string, and a blind mode that executes commands while forcing a benign exit path. (2) Containerfile builds a Debian-based lab image, downloads/install rclone 1.73.3, and starts rclone rcd bound to 0.0.0.0:5572. (3) run.sh builds and runs the container with Podman and publishes port 5572. (4) shell.sh opens an interactive shell in the running container. README identifies the repo as a test environment and references the advisory. Overall purpose: provide a reproducible local lab plus an operational Python exploit for unauthenticated or weakly exposed rclone RC services vulnerable to backend option command injection, yielding arbitrary command execution.
This repository is a small standalone proof-of-concept exploit for CVE-2026-41179, an unauthenticated RCE in rclone's RC API. It contains 5 files: two Dockerfiles for building vulnerable and patched lab containers, a bash reverse-shell payload (poc.sh), a README with the vulnerability explanation and exploitation workflow, and an instructions file duplicating the attack steps with sample output. The exploit capability is straightforward and operational: it abuses POST requests to the unauthenticated RC endpoint /operations/fsinfo, supplying a crafted fs=:webdav string with bearer_token_command to force rclone to execute arbitrary OS commands. The provided workflow uses three sequential commands: download a shell script to /tmp/shell.sh using /usr/bin/curl from an attacker HTTP server, chmod it executable with /bin/chmod, and execute it to obtain a reverse shell. Repository structure and purpose: - Dockerfile.rclone builds a Debian-based vulnerable lab image with rclone v1.69.3, exposes port 5572, and starts rclone rcd bound to 0.0.0.0:5572. - patched.Dockerfile.rclone builds a comparison image with rclone v1.73.5 to verify remediation. - poc.sh is the payload that opens a bash reverse shell to an operator-supplied host/port. - README.md documents the vulnerability, attack chain, setup, exploitation, and remediation. - instructions is a concise operator walkthrough with exact curl commands and sample shell output. This is not a scanner or detection script; it is a real exploit PoC intended for lab use. It targets network-accessible rclone RC services with no authentication, and the end result is remote command execution as the rclone process user, demonstrated as root inside the provided container.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated local command execution vulnerability in Rclone's RC endpoint `operations/fsinfo`, caused by missing authentication requirements and attacker-controlled backend initialization via WebDAV `bearer_token_command`.
Unknown
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.