[NotCVE-2026-0014] Input Leap 3.0.3 Drag-and-Drop File Transfer Path Traversal Allows Arbitrary File Write Outside the Drop Directory
Input Leap 3.0.3 path traversal lets a connected peer write files outside the drop directory.
NotCVE-2026-0014 covers improper pathname limitation in Input Leap 3.0.3's drag-and-drop file transfer. A connected peer can write a file outside the configured drop-target directory. The advisory does not cite a CVE or say the issue is being exploited.
- Drag-and-drop file transfer does not properly limit pathnames.
- A connected peer can write outside the configured drop directory.
- Affects Input Leap 3.0.3 and is tracked as NotCVE-2026-0014.
Posted by advisories on Sep 26 ---------------------------------------------------------------------------- NotCVE Advisory — NotCVE-2026-0014 ---------------------------------------------------------------------------- [-] Summary: Improper limitation of a pathname in the drag-and-drop file transfer feature of Input Leap, the open-source keyboard and mouse sharing tool, allows a connected peer to write a file outside the configured drop-target directory. Writing into the...
This source does not provide full text. Read it at seclists.org.