Directory Traversal Vulnerability in Input Leap on Windows and macOS
CVE-2026-100230

5.3MEDIUM

Key Information:

Vendor

Input-leap

Vendor
CVE Published:
25 September 2026

What is CVE-2026-100230?

A vulnerability exists in Input Leap (version 3.0.3) that allows directory traversal due to the mishandling of file path distinctions between forward and backward slashes on Windows and macOS when the non-default --enable-drag-drop option is enabled. This flaw could enable an attacker to execute arbitrary code if a malicious file is written to a startup directory using a DDRG message, posing significant security risks to systems utilizing this software.

Affected Version(s)

Input Leap Windows 0 <= 3.0.3

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.