Input Leap 3.0.3 path traversal and Windows privilege flaws
Two NotCVE advisories say Input Leap through 3.0.3 allows path-traversal file writes and unauthenticated Windows command execution as SYSTEM.
Two advisories, first posted on oss-security on 2026-09-25 and republished on Full Disclosure on 2026-09-27, describe separate flaws in Input Leap. NotCVE-2026-0014 says version 3.0.3's drag-and-drop file transfer improperly limits pathnames, allowing a connected peer to write a file outside the configured drop-target directory. NotCVE-2026-0015 says Input Leap through 3.0.3 lacks authentication on a critical function in the input-leapd daemon; on Windows a local low-privileged user can use that IPC interface to execute arbitrary commands as NT AUTHORITY\SYSTEM. The four notices agree on those details and do not contradict one another. None assigns a standard CVE, cites a patch, or reports exploitation in the wild.
- NotCVE-2026-0014 affects Input Leap 3.0.3 drag-and-drop file transfer because pathnames are not properly limited.
- A connected peer can write a file outside the configured drop-target directory.
- NotCVE-2026-0015 affects Input Leap through version 3.0.3 on Windows.
- input-leapd exposes an unauthenticated IPC function that a local low-privileged user can use to run arbitrary commands as NT AUTHORITY\SYSTEM.
- Both notices were posted on oss-security on 2026-09-25 and republished on Full Disclosure on 2026-09-27.
- None of the reports assigns a standard CVE, mentions a patch, or reports observed exploitation.
Coverage timelineoldest first · each row is one article
- · 1d ago[NotCVE-2026-0014] Input Leap 3.0.3 Drag-and-Drop File Transfer Path Traversal Allows Arbitrary File Write Outside the Drop Directory
oss-security· 34
Input Leap 3.0.3 lets a connected peer write files outside the drag-and-drop directory via path traversal.
- · 1d ago[NotCVE-2026-0015] Input Leap through 3.0.3 input-leapd Unauthenticated IPC Command Execution Allows Local Privilege Escalation to SYSTEM
oss-security· 47
Input Leap through 3.0.3 lets a local Windows user run commands as SYSTEM via unauthenticated IPC.
- · 3h ago