Path Traversal Vulnerability in RustDesk for macOS
CVE-2026-73102
6.9MEDIUM
What is CVE-2026-73102?
RustDesk versions 1.3.9 through 1.4.9 are impacted by a path traversal vulnerability within the macOS clipboard file-paste functionality. The flaw allows a malicious remote peer to exploit file descriptor names, potentially writing to unintended directories outside the designated target path. This occurs because the application does not enforce normalized relative paths when handling file descriptor names. The vulnerability can lead to unauthorized file access and modification, highlighting the need for secure path validation. A patch has been implemented to address the issue by properly validating descriptor names to prevent such exploitations.
Affected Version(s)
rustdesk 1.3.9 <= 1.4.9
rustdesk 6f1eb164d616e0e2bfbcf8c6b7c8083b09d7ed06
