[NotCVE-2026-0014] Input Leap 3.0.3 Drag-and-Drop File Transfer Path Traversal Allows Arbitrary File Write Outside the Drop Directory
Input Leap 3.0.3 lets a connected peer write files outside the drag-and-drop directory via path traversal.
An oss-security advisory labeled NotCVE-2026-0014 describes a path traversal in Input Leap 3.0.3's drag-and-drop file transfer. Improper pathname limits let a connected peer write a file outside the configured drop-target directory. The published excerpt does not mention a patch, a standard CVE assignment, or observed exploitation.
- NotCVE-2026-0014 affects Input Leap 3.0.3 drag-and-drop file transfer.
- A connected peer can write outside the configured drop directory.
- The issue is improper pathname limitation during file transfer.
Posted by advisories on Sep 25 ---------------------------------------------------------------------------- NotCVE Advisory — NotCVE-2026-0014 ---------------------------------------------------------------------------- [-] Summary: Improper limitation of a pathname in the drag-and-drop file transfer feature of Input Leap, the open-source keyboard and mouse sharing tool, allows a connected peer to write a file outside the configured drop-target directory. Writing into the...
This source does not provide full text. Read it at seclists.org.