Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3148 articles · 163374 vulns · 38/41 feeds (7d)
← Back to list
EST
PRE-CVE

rcp Directory Traversal and Command Injection Vulnerability

60% confidence

Description

The 'rcp' utility's receive path (sink()) concatenates server-supplied filenames into the local destination path without validating directory traversal sequences (e.g., '../') or shell metacharacters. This allows a malicious or MITM server to write files outside the intended directory or execute arbitrary commands via crafted filenames.

Affected Products

VendorProductVersions
—rcp—

Related News (1 articles)

Tier C
oss-security2h ago
'rcp' and friends meet escape characters and quoting
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
CWECWE-22, CWE-78
PublishedJun 16, 2026
Last enriched2h ago
Tags
directory-traversalcommand-injection
Trending Score27
Source articles1
Independent1
Info Completeness6/14
Missing: cve_id, vendor, versions, cvss, epss, kev, patch, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: reported
Confidence: 60%

Vulnerability Timeline

CVE Published
Jun 16, 2026
Exploit Available
Jun 16, 2026
Discovered by ZDM
Jun 16, 2026