CVE-2026-100388: RustDesk before 1.5.0 Missing Authorization Check on Incoming File Clipboard Messages
RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages in the Cliprdr message handler on Linux and macOS. Authenticated remote peers with disabled file transfer permissions can place files onto the host clipboard and retrieve copied files and contents from the process-wide clipboard cache.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
RustDeskto a version that resolves this vulnerability.Fixed in 1.5.0
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated remote peer can exploit it during a RustDesk session. The issue affects Linux and macOS hosts when file transfer permissions have been disabled for that peer.
Are systems with file transfer disabled protected?
No. In affected versions, disabling file transfer permissions does not prevent an authenticated remote peer from using incoming file clipboard messages to place files on the host clipboard or retrieve copied files and clipboard contents from the process-wide cache.
Which versions are affected?
RustDesk versions before 1.5.0 are affected. Updating to version 1.5.0 or later addresses the missing authorization check.