CVE-2026-100230: Medium severity Input Leap Input Leap vulnerability
Published Sep 25, 2026
·Updated
Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on Windows or macOS, mishandles the / versus \ distinction and allows directory traversal, with resultant code execution if a file is written to a startup directory. This occurs via a DDRG message.
Affected Software
1 affected component
Input Leap Input Leap<=3.0.3
Event History
Sep 25, 2026
CVE Published
via MITRE·03:31 PM
Data Sourced
via MITRE·03:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
The issue affects Input Leap through 3.0.3 on Windows or macOS only when the non-default --enable-drag-drop option is enabled.
2
What access does an attacker need to exploit this?
The attacker needs low-level privileges and network access, and exploitation is performed through a DDRG message. The attack complexity is high and no user interaction is required.
3
What makes this vulnerability lead to code execution?
The path traversal can result in code execution if the attacker causes a file to be written into a startup directory.