Description
Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on Windows or macOS, mishandles the / versus \ distinction and allows directory traversal, with resultant code execution if a file is written to a startup directory. This occurs via a DDRG message.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 25 Sep 2026 15:45:00 +0000
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-25T15:35:14.634Z
Reserved: 2026-09-25T15:31:52.007Z
Link: CVE-2026-100230
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-180
Incorrect Behavior Order: Validate Before Canonicalize