CVE-2026-73102

Published Aug 26, 2026

Last updated 11 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-73102 is a path traversal vulnerability found in RustDesk versions 1.3.9 through 1.4.9, specifically impacting the macOS clipboard file-paste functionality. The vulnerability arises because the application accepts file descriptor names provided by a peer and incorporates them into the target directory without adequately normalizing relative paths. This flaw allows a remote peer engaged in an active clipboard file-paste session to utilize parent-directory components or absolute paths. This enables them to write files to locations outside the designated target directory, provided those locations are writable by the RustDesk process. The issue has been addressed by implementing validation for descriptor names and ensuring safe path joining.

Description
RustDesk versions 1.3.9 through 1.4.9 contain a path traversal vulnerability in the macOS clipboard file-paste code path. The application accepts peer-supplied file descriptor names and joins them to the selected target directory without requiring normalized relative paths. A remote peer in an active clipboard file-paste session can use parent-directory components or absolute paths to write files outside the intended target directory at locations writable by the RustDesk process. Commit 6f1eb16 fixes the issue by validating descriptor names and safely joining paths.
Source
disclosure@vulncheck.com
NVD status
Deferred

Risk scores

CVSS 4.0

Type
Secondary
Base score
6.9
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
MEDIUM

CVSS 3.1

Type
Primary
Base score
5.7
Impact score
3.6
Exploitability score
2.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Severity
MEDIUM

Weaknesses

disclosure@vulncheck.com
CWE-22

Social media

Hype score
Not currently trending