CVE-2026-28373

The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property. A malicious export can write arbitrary content to any path on the victim's filesystem.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:stackfield:stackfield:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-03 17:16

Updated : 2026-07-24 22:10


NVD link : CVE-2026-28373

Mitre link : CVE-2026-28373

CVE.ORG link : CVE-2026-28373


JSON object : View

Products Affected

stackfield

  • stackfield

microsoft

  • windows

apple

  • macos
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')