CVE-2026-53793

rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the intended inner-module root confinement by constructing paths that resolve outside the chroot boundary when the module root contains a /./ boundary marker. Attackers can exploit improper handling of the /./ notation or forge delta-basis transfers referencing xname paths that cross the /./ boundary to gain unauthorized read or write access to files outside the module's subtree.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-13 15:19

Updated : 2026-09-08 20:28


NVD link : CVE-2026-53793

Mitre link : CVE-2026-53793

CVE.ORG link : CVE-2026-53793


JSON object : View

Products Affected

No product.

CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')