{"id":"JLSEC-2025-326","summary":"A path traversal vulnerability exists in rsync","details":"A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification coupled with deduplication checks occurring on a per-file-list basis could allow a server to write files outside of the client's intended destination directory. A malicious server could write malicious files to arbitrary locations named after valid directories/paths on the client.","modified":"2026-07-18T00:01:14.789246793Z","published":"2025-11-25T22:50:06.167Z","upstream":["CVE-2024-12087"],"database_specific":{"license":"CC-BY-4.0","sources":[{"html_url":"https://nvd.nist.gov/vuln/detail/CVE-2024-12087","database_specific":{"status":"Modified"},"id":"CVE-2024-12087","imported":"2026-07-17T21:00:19.659Z","modified":"2026-06-30T00:16:48.573Z","published":"2025-01-14T18:15:25.467Z","url":"https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2024-12087"}]},"references":[{"type":"WEB","url":"https://access.redhat.com/errata/RHBA-2025:6470"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:23154"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:23235"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:23407"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:23415"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:23416"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:23842"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:23853"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:23854"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:23858"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:2600"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:7050"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:8385"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2024-12087"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2330672"},{"type":"WEB","url":"https://github.com/google/security-research/security/advisories/GHSA-p5pg-x43v-mvqj"},{"type":"WEB","url":"https://kb.cert.org/vuls/id/952657"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/01/msg00008.html"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20250131-0002/"},{"type":"WEB","url":"https://www.kb.cert.org/vuls/id/952657"}],"affected":[{"package":{"name":"rsync_jll","ecosystem":"Julia","purl":"pkg:julia/rsync_jll?uuid=191d6b87-264a-55f5-a0e2-c8fbce9a1ce0"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.4.0+0"}]}],"database_specific":{"source":"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2025/JLSEC-2025-326.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}