Security researchers at Google have uncovered vulnerabilities in the rsync server and client that could allow remote code execution and other malicious activities. The post details specific vulnerabilities (CVE-2024-12084 and CVE-2024-12085) that can lead to remote code execution, as well as how a rogue server could exploit the rsync client to access files and create unsafe symlinks.