{"apiVersion":"1.0","identifier":"CVE-2026-70460","description":"rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under the module root, or who can exploit a pre-existing trusted symlink, can direct file writes to locations outside the intended module root, achieving arbitrary file write relative to the module root parent.","publishedAt":"2026-08-13T15:19:59","lastModifiedAt":"2026-08-14T16:16:59","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-70460","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","epssProbability":0.00448,"riskScore":0.84,"affectedProduct":"rsync","affectedVersions":"<3.5.0","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-70460","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-70460","en":"https://www.redsauce.net/en/cves/CVE-2026-70460","fr":"https://www.redsauce.net/fr/cves/CVE-2026-70460","pt":"https://www.redsauce.net/pt/cves/CVE-2026-70460","de":"https://www.redsauce.net/de/cves/CVE-2026-70460","sk":"https://www.redsauce.net/sk/cves/CVE-2026-70460","el":"https://www.redsauce.net/el/cves/CVE-2026-70460"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-70460"}}