CVE-2026-73102
Last modified
CVE-2026-73102 is a medium-severity vulnerability rated 5.7/10 on the CVSS scale. RustDesk versions 1.3.9 through 1.4.9 contain a path traversal vulnerability in the macOS clipboard file-paste code path. The application accepts peer-supplied file descriptor names and joins them to the selected target directory without requiring normalized relative paths. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
RustDesk versions 1.3.9 through 1.4.9 contain a path traversal vulnerability in the macOS clipboard file-paste code path. The application accepts peer-supplied file descriptor names and joins them to the selected target directory without requiring normalized relative paths. A remote peer in an active clipboard file-paste session can use parent-directory components or absolute paths to write files outside the intended target directory at locations writable by the RustDesk process. Commit 6f1eb16 fixes the issue by validating descriptor names and safely joining paths.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-73102?
How severe is CVE-2026-73102?
How do I fix CVE-2026-73102?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-73087Dozzle is a realtime log viewer for docker containers. From …2.3
- CVE-2026-73088Browserslist is a configuration tool for sharing target brow…7.5
- CVE-2026-73089Browserslist is a configuration tool for sharing target brow…7.5
- CVE-2026-7309A flaw was found in the OpenShift Container Platform build s…4.3
- CVE-2026-73090PeerTube is an ActivityPub-federated video streaming platfor…9.3
- CVE-2026-7310A heap-based buffer overflow vulnerability exists in XML par…4.4
- CVE-2026-73103Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-73104Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-73105Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-73106Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-73107Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-73108RustDesk versions before 1.4.7 contain an uncontrolled specu…7.5
Are you affected by CVE-2026-73102?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
