Unknown · Nitroshare-Desktop · CVE-2026-66050
**Name of the Vulnerable Software and Affected Versions**
NitroShare Desktop versions prior to 0.3.5
**Description**
The LAN file transfer server contains a path traversal issue that allows unauthenticated attackers on the same network to write arbitrary files. This occurs because the server fails to validate paths when processing the `name` field within the JSON item header. By sending a crafted filename containing directory traversal sequences, an attacker can write files outside the intended transfer root directory to any location where the current user has write permissions, such as the Windows Startup folder, which can lead to persistent code execution upon the next user login.
**Recommendations**
Update NitroShare Desktop to version 0.3.5 or later.