PT-2026-82092 · Rustdesk · Rustdesk

CVE-2026-73102

·

Published

2026-08-26

·

Updated

2026-08-30

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RustDesk versions 1.3.9 through 1.4.9
Description A path traversal issue exists in the macOS clipboard file-paste code path. The application accepts file descriptor names provided by a peer and joins them to the target directory without requiring normalized relative paths. This allows a remote peer in an active clipboard file-paste session to use absolute paths or parent-directory components to write files outside the intended target directory in locations where the RustDesk process has write permissions.
Recommendations Update RustDesk versions 1.3.9 through 1.4.9 to a version that includes commit 6f1eb16 to ensure descriptor names are validated and paths are joined safely.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73102

Affected Products

Rustdesk