CVE-2026-100230 PUBLISHED

Assigner: mitre
Reserved: 25.09.2026 Published: 25.09.2026 Updated: 25.09.2026

Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on Windows or macOS, mishandles the / versus \ distinction and allows directory traversal, with resultant code execution if a file is written to a startup directory. This occurs via a DDRG message.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS Score: 5.3

Product Status

Vendor input-leap
Product Input Leap
Versions Default: unknown
  • affected from 0 to 3.0.3 (incl.)

References

Problem Types

  • CWE-180 Incorrect Behavior Order: Validate Before Canonicalize CWE