Executive brief
RustDesk is a remote desktop application used to access computers over networks. Versions 1.3.9 through 1.4.9 on macOS contain a flaw in the clipboard file-paste feature that allows a connected remote user to write files outside the intended target directory, potentially overwriting or creating files in sensitive locations. This could enable an attacker to modify application configuration, inject malicious content, or compromise system integrity.
Technical details
The vulnerability is a path traversal flaw in RustDesk's macOS clipboard file-paste handler. The application accepts peer-supplied file descriptor names and joins them to a target directory without validating for normalized relative paths. An attacker can leverage parent-directory components ("../") or absolute paths in the descriptor name to write files outside the intended target directory, as long as those locations are writable by the RustDesk process. Exploitation requires an active clipboard file-paste session with a remote peer. The fix (commit 6f1eb16) adds validation of descriptor names and safe path-joining logic to prevent traversal.
Affected products
- RustDesk RustDesk 1.3.9 through 1.4.9
Timeline
- 2026-08-26: disclosed
- 2026-08-04: patched: Fix merged in commit 6f1eb16