File Transfer Permission Flaw in RustDesk on Linux and macOS
CVE-2026-100388
5.3MEDIUM
What is CVE-2026-100388?
Versions of RustDesk prior to 1.5.0 exhibit a vulnerability that inadequately validates file transfer permissions on incoming clipboard messages within the Cliprdr message handler for Linux and macOS. This flaw allows authenticated remote peers, who have disabled file transfer permissions, to improperly place files onto the host clipboard and access copied files and data from the process-wide clipboard cache, potentially leading to unauthorized information retrieval and data exposure.
Affected Version(s)
rustdesk 0 < 1.5.0
rustdesk 1.5.0
