Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the intended destination tree by specifying an absolute path via --temp-dir or --link-dest options. The rename-confinement logic is bypassed when these options resolve to paths outside the destination tree, enabling attacker-controlled values to write files to arbitrary locations accessible to the rsync process. | |
| Title | rsync < 3.5.0 Arbitrary File Write via --temp-dir/--link-dest | |
| Weaknesses | CWE-59 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T14:39:26.044Z
Reserved: 2026-06-10T20:14:32.827Z
Link: CVE-2026-53795
No data.
Status : Received
Published: 2026-08-13T15:19:44.117
Modified: 2026-08-13T15:19:44.117
Link: CVE-2026-53795
No data.
OpenCVE Enrichment
No data.