This issue affects RustDesk Client: through 1.4.5.
Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
Synchronize privilege logic between CLI and GUI. Require user confirmation. Add config to disable.
Workaround
Unregister the rustdesk:// URI scheme handler at OS level
Wed, 25 Mar 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple iphone Os Apple macos Google android Linux Linux linux Kernel Microsoft Microsoft windows Rustdesk Rustdesk rustdesk |
|
| CPEs | cpe:2.3:a:rustdesk:rustdesk:*:*:*:*:webclient:*:*:* cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe:2.3:o:google:android:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Apple
Apple iphone Os Apple macos Google android Linux Linux linux Kernel Microsoft Microsoft windows Rustdesk Rustdesk rustdesk |
|
| Metrics |
cvssV3_1
|
Tue, 17 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Thu, 05 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 05 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 05 Mar 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, FFI bridge modules) allows Privilege Escalation. This vulnerability is associated with program files flutter/lib/common.Dart, src/flutter_ffi.Rs and program routines URI handler for rustdesk://password/, bind.MainSetPermanentPassword(). This issue affects RustDesk Client: through 1.4.5. | |
| Title | RustDesk Flutter URI Handler Sets Permanent Password Without Privilege Check or User Confirmation | |
| First Time appeared |
Rustdesk-client
Rustdesk-client rustdesk Client |
|
| Weaknesses | CWE-285 CWE-352 |
|
| CPEs | cpe:2.3:a:rustdesk-client:rustdesk_client:*:*:android:*:*:*:*:* cpe:2.3:a:rustdesk-client:rustdesk_client:*:*:ios:*:*:*:*:* cpe:2.3:a:rustdesk-client:rustdesk_client:*:*:linux:*:*:*:*:* cpe:2.3:a:rustdesk-client:rustdesk_client:*:*:macos:*:*:*:*:* cpe:2.3:a:rustdesk-client:rustdesk_client:*:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Rustdesk-client
Rustdesk-client rustdesk Client |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VULSec
Published:
Updated: 2026-03-17T14:30:50.566Z
Reserved: 2026-03-05T14:13:37.203Z
Link: CVE-2026-30793
Updated: 2026-03-05T16:37:05.264Z
Status : Analyzed
Published: 2026-03-05T16:16:20.037
Modified: 2026-03-25T15:34:35.820
Link: CVE-2026-30793
No data.
OpenCVE Enrichment
Updated: 2026-03-06T15:07:34Z