CVE Vulnerabilities

CVE-2026-100230

Incorrect Behavior Order: Validate Before Canonicalize

Published: Sep 25, 2026 | Modified: Sep 25, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

Input Leap (aka input-leap) through 3.0.3, when the non-default –enable-drag-drop option is used on Windows or macOS, mishandles the / versus distinction and allows directory traversal, with resultant code execution if a file is written to a startup directory. This occurs via a DDRG message.

Weakness

The product validates input before it is canonicalized, which prevents the product from detecting data that becomes invalid after the canonicalization step.

Potential Mitigations

References