Skip to content
Rota Nacional

Cyber ·

Input Leap 3.0.3: file-transfer flaw

A notice published on September 25, 2026 describes a path-traversal flaw in Input Leap 3.0.3’s drag-and-drop feature. A connected device may write files outside the configured receiving directory.

A NotCVE notice, identified as NotCVE-2026-0014, reports a flaw in Input Leap 3.0.3, open-source software for sharing a keyboard and mouse. The item was automatically translated from a post in the oss-sec feed, dated September 25, 2026.

According to the summary, inadequate path validation in the drag-and-drop file-transfer feature may let a connected device write files outside the configured receiving directory. The supplied text gives no exploitation details, additional impact, or available fix.

To assess the risk, consult the full notice and confirm affected versions and conditions before taking action. Restrict connections to trusted devices and, if file transfer is not needed, consider disabling it while checking official guidance.

Check the original notice for technical details and updates, then compare them with your organization’s inventory and configuration. If you use AI to summarize or apply the material, remove internal data, credentials, and identifiers before submitting it.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free