Rustdesk · Rustdesk · CVE-2026-100388
**Name of the Vulnerable Software and Affected Versions**
RustDesk versions prior to 1.5.0
**Description**
On Linux and macOS, the `Cliprdr` message handler fails to properly validate file transfer permissions for incoming file clipboard messages. This allows authenticated remote peers, even those with file transfer permissions disabled, to place files onto the host clipboard and retrieve copied files and contents from the process-wide clipboard cache.
**Recommendations**
Update to version 1.5.0 or later.