Vendor
Rsync versions prior to 3.5.0 contain an arbitrary file write vulnerability that allows attackers to bypass path confinement by providing absolute paths to specific command-line options.