CVE-2026-100230

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on Windows or macOS, mishandles the / versus \ distinction and allows directory traversal, with resultant code execution if a file is written to a startup directory. This occurs via a DDRG message.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-180

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-26: 109-26
Referenced assets1 URL
By indicator
Full discourse1 post
  • NotCVE@notCVE

    🎯 A NotCVE became a CVE NotCVE-2026-0014 — registered 2026-09-24, no CVE assigned at the time. CVE-2026-100230 — published 1 days later. The record was there from day one — public and timestamped. Details → https://notcve.org/notcve/NotCVE-2026-0014 https://t.co/8F58zldJDm

    0000026
    73 followersView on X

Explore more