Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-73102— RustDesk Path Traversal via macOS Clipboard File-Paste

Quick assessment

Affected
rustdesk rustdesk
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

RustDesk 1.3.9 至 1.4.9 版本中,macOS 端剪贴板文件粘贴代码路径存在路径遍历漏洞。该应用接受对端提供的文件描述符名称,并将其直接拼接到选定的目标目录,而未强制要求规范化相对路径。在活跃的剪贴板文件粘贴会话中,远程对端可利用上级目录组件或绝对路径,将文件写入预期目标目录之外的、且 RustDesk 进程可写的其他位置。提交 6f1eb16 通过验证描述符名称并安全地拼接路径来修复了该问题。

CVSS 5.7 · Medium

Possible ATT&CK Techniques 1 AI

T1105 · Ingress Tool Transfer

Affected Version Matrix 2

VendorProduct Version RangeStatus
rustdesk rustdesk 1.3.9≤ 1.4.9 affected
6f1eb164d616e0e2bfbcf8c6b7c8083b09d7ed06 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-73102

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
RustDesk Path Traversal via macOS Clipboard File-Paste
Source: CVE Program / CVE List V5
Vulnerability Description
RustDesk versions 1.3.9 through 1.4.9 contain a path traversal vulnerability in the macOS clipboard file-paste code path. The application accepts peer-supplied file descriptor names and joins them to the selected target directory without requiring normalized relative paths. A remote peer in an active clipboard file-paste session can use parent-directory components or absolute paths to write files outside the intended target directory at locations writable by the RustDesk process. Commit 6f1eb16 fixes the issue by validating descriptor names and safely joining paths.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
rustdesk rustdesk 1.3.9 ~ 1.4.9 -

II. Public POCs for CVE-2026-73102

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-73102

登录查看更多情报信息。

Patches & Fixes for CVE-2026-73102 (1)

Vendor Advisories for CVE-2026-73102 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-73102

No comments yet


Leave a comment