MEDIUM
input-leap
CVE published 2026-09-25
CVE-2026-100230
CVE-2026-100230 is a directory traversal vulnerability in Input Leap version 3.0.3 and earlier, when the --enable-drag-drop option is used on Windows or macOS. The vulnerability allows an attacker to write files to a startup directory, potentially leading to code execution. This occurs via mishandling of the / versus distinction in Input Leap's Drag and Drop functionality, allowing directory traversal. Th [truncated]