{"id":"CVE-2026-70460","summary":"rsync 2.3.3 \u003c 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink","details":"rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under the module root, or who can exploit a pre-existing trusted symlink, can direct file writes to locations outside the intended module root, achieving arbitrary file write relative to the module root parent.","aliases":["GHSA-w3xf-j2r2-gv4x"],"modified":"2026-08-16T03:31:28.731520499Z","published":"2026-08-13T14:43:06.250Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-22","CWE-59"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70460.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70460.json"},{"type":"ADVISORY","url":"https://github.com/RsyncProject/rsync/releases/tag/v3.5.0"},{"type":"ADVISORY","url":"https://github.com/RsyncProject/rsync/security/advisories/GHSA-w3xf-j2r2-gv4x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-70460"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/rsync-path-traversal-via-partial-dir-backup-dir-symlink"},{"type":"PACKAGE","url":"https://github.com/RsyncProject/rsync"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/rsyncproject/rsync","events":[{"introduced":"461c6de1a8f2d6eac44e607c6862f356915e579d"},{"fixed":"471e17dc0d68233db84db11be82c9f62f4661214"}],"database_specific":{"extracted_events":[{"introduced":"2.3.3"},{"last_affected":"3.4.4"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-70460.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}