PatchSiren

input-leap CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM input-leap CVE published 2026-09-25

CVE-2026-100230

CVE-2026-100230 is a directory traversal vulnerability in Input Leap version 3.0.3 and earlier, when the --enable-drag-drop option is used on Windows or macOS. The vulnerability allows an attacker to write files to a startup directory, potentially leading to code execution. This occurs via mishandling of the / versus distinction in Input Leap's Drag and Drop functionality, allowing directory traversal. Th [truncated]