{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/rsync-2.0.0-3.4.9/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-53790"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["rsync","rsync (2.0.0-3.4.9)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","command-injection","rsync","file-transfer","cve-2026-53793","denial-of-service","network"],"_cs_type":"advisory","_cs_vendors":["Samba"],"content_html":"\u003cp\u003eThe rsync utility, in versions prior to 3.5.0, is affected by multiple command and argument injection vulnerabilities. These flaws reside in several code paths including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and remote-shell command newline injection. The vulnerability stems from insufficient sanitization of user-supplied inputs, specifically hostnames and hostspecs passed to the utility. An attacker providing crafted input containing shell metacharacters or newline characters can achieve command injection, leading to execution of arbitrary code with the privileges of the user running the rsync process. This affects any system leveraging rsync for file synchronization or as a backend for transfer services. Defenders should prioritize updating rsync to version 3.5.0 or later to mitigate the risk of arbitrary command execution across Linux, macOS, and Windows environments.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary command execution on systems where rsync is invoked with attacker-controlled inputs. This poses a significant risk to servers, build systems, and automated backup pipelines that rely on rsync for remote data synchronization. Unauthorized code execution can lead to full system compromise, data exfiltration, or lateral movement within the network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the rsync binary to version 3.5.0 or higher across all affected server and workstation environments to patch CVE-2026-53790.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation for any automated scripts, web interfaces, or command-line wrappers that pass user-supplied strings as hostnames or parameters to rsync.\u003c/li\u003e\n\u003cli\u003eAudit environment variables, specifically RSYNC_CONNECT_PROG, in automated execution environments to ensure they are not influenced by untrusted input sources.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T16:56:33Z","date_published":"2026-08-13T15:38:06Z","id":"https://feed.craftedsignal.io/briefs/2026-08-rsync-injection/","summary":"Versions of rsync prior to 3.5.0 contain multiple command and argument injection flaws that allow attackers to execute arbitrary code via malicious hostnames, environment variables, and shell command injections.","title":"Multiple Command and Argument Injection Vulnerabilities in rsync","url":"https://feed.craftedsignal.io/briefs/2026-08-rsync-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Rsync (2.0.0-3.4.9)","version":"https://jsonfeed.org/version/1.1"}