{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-79777","assignerOrgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","state":"PUBLISHED","assignerShortName":"VulnCheck","dateReserved":"2026-08-25T14:29:43.528Z","datePublished":"2026-08-25T15:16:07.745Z","dateUpdated":"2026-08-28T22:25:36.423Z"},"containers":{"cna":{"providerMetadata":{"orgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","shortName":"VulnCheck","dateUpdated":"2026-08-25T15:16:07.745Z"},"datePublic":"2026-07-31T00:00:00.000Z","title":"rclone before v1.75.0 Information Disclosure via RC API","descriptions":[{"lang":"en","value":"rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses."}],"problemTypes":[{"descriptions":[{"lang":"en","description":"Generation of Error Message Containing Sensitive Information","cweId":"CWE-209","type":"CWE"}]}],"affected":[{"vendor":"rclone","product":"rclone","defaultStatus":"unaffected","packageURL":"pkg:golang/github.com/rclone/rclone","versions":[{"version":"0","status":"affected","versionType":"semver","lessThan":"1.75.0"},{"version":"1.75.0","status":"unaffected","versionType":"semver"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:*","versionEndExcluding":"1.75.0"}]}]}],"metrics":[{"format":"CVSS","cvssV4_0":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","baseScore":5.1,"baseSeverity":"MEDIUM"}},{"format":"CVSS","cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.7,"baseSeverity":"LOW"}}],"references":[{"url":"https://github.com/rclone/rclone/security/advisories/GHSA-gwfq-86j8-7qhv","tags":["vendor-advisory"],"name":"GitHub Security Advisory (GHSA-gwfq-86j8-7qhv)"},{"name":"VulnCheck Advisory: rclone before v1.75.0 Information Disclosure via RC API","tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/rclone-before-information-disclosure-via-rc-api"}],"credits":[{"lang":"en","value":"SnailSploit","type":"reporter"},{"lang":"en","value":"ncw","type":"finder"}],"x_generator":{"engine":"vulncheck-endgame"}},"adp":[{"references":[{"url":"https://github.com/rclone/rclone/security/advisories/GHSA-gwfq-86j8-7qhv","tags":["exploit"]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-28T22:25:13.992087Z","id":"CVE-2026-79777","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-28T22:25:36.423Z"}}]}}