Path Traversal Vulnerability in RustDesk for macOS
CVE-2026-73102

6.9MEDIUM

Key Information:

Vendor

Rustdesk

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-73102?

RustDesk versions 1.3.9 through 1.4.9 are impacted by a path traversal vulnerability within the macOS clipboard file-paste functionality. The flaw allows a malicious remote peer to exploit file descriptor names, potentially writing to unintended directories outside the designated target path. This occurs because the application does not enforce normalized relative paths when handling file descriptor names. The vulnerability can lead to unauthorized file access and modification, highlighting the need for secure path validation. A patch has been implemented to address the issue by properly validating descriptor names to prevent such exploitations.

Affected Version(s)

rustdesk 1.3.9 <= 1.4.9

rustdesk 6f1eb164d616e0e2bfbcf8c6b7c8083b09d7ed06

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.