PT-2026-82092 · Rustdesk · Rustdesk
CVE-2026-73102
·
Published
2026-08-26
·
Updated
2026-08-30
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RustDesk versions 1.3.9 through 1.4.9
Description
A path traversal issue exists in the macOS clipboard file-paste code path. The application accepts file descriptor names provided by a peer and joins them to the target directory without requiring normalized relative paths. This allows a remote peer in an active clipboard file-paste session to use absolute paths or parent-directory components to write files outside the intended target directory in locations where the RustDesk process has write permissions.
Recommendations
Update RustDesk versions 1.3.9 through 1.4.9 to a version that includes commit 6f1eb16 to ensure descriptor names are validated and paths are joined safely.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rustdesk