{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/rsyncproject/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-53795"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["rsync"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["RsyncProject"],"content_html":"\u003cp\u003eRsync versions prior to 3.5.0 are vulnerable to an arbitrary file write vulnerability (CVE-2026-53795) caused by improper handling of absolute paths. When an attacker provides absolute paths via the --temp-dir or --link-dest command-line options, the application fails to correctly apply rename-confinement logic. This failure permits the rsync process to write files to locations outside the intended destination directory, provided those locations are writable by the user executing the rsync process. This vulnerability poses a significant risk to systems that process untrusted rsync inputs or automated synchronization tasks, as it could be leveraged to overwrite sensitive configuration files or inject malicious binaries, potentially leading to privilege escalation or system compromise.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an automated system or user process executing rsync with user-controllable arguments.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious rsync command that includes the --temp-dir or --link-dest options.\u003c/li\u003e\n\u003cli\u003eAttacker specifies an absolute path for these options that targets a directory outside the intended scope.\u003c/li\u003e\n\u003cli\u003eThe rsync process initiates, processing the supplied malicious path parameters.\u003c/li\u003e\n\u003cli\u003eThe application fails to validate the absolute path against the destination tree restrictions.\u003c/li\u003e\n\u003cli\u003eThe rename-confinement check is bypassed due to logic flaws in path resolution.\u003c/li\u003e\n\u003cli\u003eThe rsync process writes a file to the attacker-defined absolute path location.\u003c/li\u003e\n\u003cli\u003eThe attacker achieves unauthorized file creation or modification on the target system.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the unauthorized creation or modification of files anywhere on the local filesystem that the rsync process has permissions to access. This can result in system instability, the injection of malicious scripts into cron jobs, or the overwriting of SSH authorized_keys, ultimately leading to full system compromise or persistence for the attacker.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate rsync to version 3.5.0 or later on all systems to remediate CVE-2026-53795.\u003c/li\u003e\n\u003cli\u003eAudit scripts and automation pipelines for rsync commands that utilize --temp-dir or --link-dest flags with untrusted input.\u003c/li\u003e\n\u003cli\u003eRestrict the permissions of the user accounts executing rsync to the minimum necessary directory access to limit the potential impact of an arbitrary file write.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T15:39:53Z","date_published":"2026-08-13T15:38:24Z","id":"https://feed.craftedsignal.io/briefs/2026-08-rsync-file-write/","summary":"Rsync versions prior to 3.5.0 contain an arbitrary file write vulnerability that allows attackers to bypass path confinement by providing absolute paths to specific command-line options.","title":"Arbitrary File Write Vulnerability in rsync","url":"https://feed.craftedsignal.io/briefs/2026-08-rsync-file-write/"}],"language":"en","title":"CraftedSignal Threat Feed - RsyncProject","version":"https://jsonfeed.org/version/1.1"}