RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages in the Cliprdr message… (CVE-2026-100388)
RustDesk versions prior to 1.5.0 contain a vulnerability in the Cliprdr message handler on Linux and macOS where file transfer permissions are not properly validated for incoming file clipboard messages. This allows authenticated remote peers, even if file transfer permissions are disabled, to place files onto the host clipboard and retrieve copied files and clipboard contents from the process-wide clipboard cache.
AI Analysis
Technical Summary
RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages handled by the Cliprdr message handler on Linux and macOS platforms. This flaw enables authenticated remote peers with disabled file transfer permissions to bypass restrictions and place files onto the host clipboard as well as retrieve copied files and clipboard contents from the process-wide clipboard cache, potentially leading to unauthorized information disclosure and integrity issues.
Potential Impact
The vulnerability allows an authenticated remote peer to bypass file transfer permission restrictions, enabling unauthorized placement of files onto the host clipboard and retrieval of clipboard contents. This can lead to limited confidentiality and integrity impacts, as indicated by the CVSS vector (Confidentiality Low, Integrity Low, Availability None). There is no indication of availability impact or known active exploitation in the wild.
Mitigation Recommendations
No official patch or remediation details are provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict or monitor authenticated remote peer access and consider disabling clipboard sharing features if possible to reduce risk.
RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages in the Cliprdr message… (CVE-2026-100388)
Description
RustDesk versions prior to 1.5.0 contain a vulnerability in the Cliprdr message handler on Linux and macOS where file transfer permissions are not properly validated for incoming file clipboard messages. This allows authenticated remote peers, even if file transfer permissions are disabled, to place files onto the host clipboard and retrieve copied files and clipboard contents from the process-wide clipboard cache.
CVSS v3.1
Score 5.4medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages handled by the Cliprdr message handler on Linux and macOS platforms. This flaw enables authenticated remote peers with disabled file transfer permissions to bypass restrictions and place files onto the host clipboard as well as retrieve copied files and clipboard contents from the process-wide clipboard cache, potentially leading to unauthorized information disclosure and integrity issues.
Potential Impact
The vulnerability allows an authenticated remote peer to bypass file transfer permission restrictions, enabling unauthorized placement of files onto the host clipboard and retrieval of clipboard contents. This can lead to limited confidentiality and integrity impacts, as indicated by the CVSS vector (Confidentiality Low, Integrity Low, Availability None). There is no indication of availability impact or known active exploitation in the wild.
Mitigation Recommendations
No official patch or remediation details are provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict or monitor authenticated remote peer access and consider disabling clipboard sharing features if possible to reduce risk.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-mr3p-q22v-cr79
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-100388"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6ab74f64f7a7c54106e14e41
Added to database: 09/26/2026, 04:51:48 UTC
Last enriched: 09/26/2026, 05:05:38 UTC
Last updated: 09/27/2026, 01:47:40 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.