Directory Traversal Vulnerability in Input Leap on Windows and macOS
CVE-2026-100230
5.3MEDIUM
What is CVE-2026-100230?
A vulnerability exists in Input Leap (version 3.0.3) that allows directory traversal due to the mishandling of file path distinctions between forward and backward slashes on Windows and macOS when the non-default --enable-drag-drop option is enabled. This flaw could enable an attacker to execute arbitrary code if a malicious file is written to a startup directory using a DDRG message, posing significant security risks to systems utilizing this software.
Affected Version(s)
Input Leap Windows 0 <= 3.0.3
