AI description
CVE-2026-73102 is a path traversal vulnerability found in RustDesk versions 1.3.9 through 1.4.9, specifically impacting the macOS clipboard file-paste functionality. The vulnerability arises because the application accepts file descriptor names provided by a peer and incorporates them into the target directory without adequately normalizing relative paths. This flaw allows a remote peer engaged in an active clipboard file-paste session to utilize parent-directory components or absolute paths. This enables them to write files to locations outside the designated target directory, provided those locations are writable by the RustDesk process. The issue has been addressed by implementing validation for descriptor names and ensuring safe path joining.
- Description
- RustDesk versions 1.3.9 through 1.4.9 contain a path traversal vulnerability in the macOS clipboard file-paste code path. The application accepts peer-supplied file descriptor names and joins them to the selected target directory without requiring normalized relative paths. A remote peer in an active clipboard file-paste session can use parent-directory components or absolute paths to write files outside the intended target directory at locations writable by the RustDesk process. Commit 6f1eb16 fixes the issue by validating descriptor names and safely joining paths.
- Source
- disclosure@vulncheck.com
- NVD status
- Deferred
CVSS 4.0
- Type
- Secondary
- Base score
- 6.9
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- MEDIUM
CVSS 3.1
- Type
- Primary
- Base score
- 5.7
- Impact score
- 3.6
- Exploitability score
- 2.1
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
- Severity
- MEDIUM
- disclosure@vulncheck.com
- CWE-22
- Hype score
- Not currently trending
🚨*CVE* CVE-2026-73102 RustDesk versions 1.3.9 through 1.4.9 contain a path traversal vulnerability in the macOS clipboard file-paste code path. The application accepts peer-supplied file d… https://t.co/ZDD3sCgLkg ----- Traducción: CVE-2026-73102 Rus… https://t.co/bYtskK
@infoflowcloud
30 Aug 2026
48 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-73102 RustDesk versions 1.3.9 through 1.4.9 contain a path traversal vulnerability in the macOS clipboard file-paste code path. The application accepts peer-supplied file d… https://t.co/85l4RLRFJi
@CVEnew
30 Aug 2026
1619 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes