CVE Explorer
CVE-2026-40254
FreeRDP is a free implementation of the Remote Desktop Protocol. Versions prior to 3.25.0 have an off-by-one in the path traversal filter in `channels/drive/client/drive_file.c`. The `contains_dotdot()` function catches `../` and `..\` mid-path but misses `..` when it's the last component with no trailing separator. A rogue RDP server can read, list, or write files one directory above the client's shared folder through RDPDR requests. This requires the victim to connect with drive redirection en
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"FreeRDP","vendor":"FreeRDP","versions":[{"status":"affected","version":"< 3.25.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:62d6b8ceeea43038b1551df8ee0ce83717c60b8a14208055be69d7bb63cc8eb9 · sha256:897ba3ffd040c3a5… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.2,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:62d6b8ceeea43038b1551df8ee0ce83717c60b8a14208055be69d7bb63cc8eb9 · sha256:897ba3ffd040c3a5… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-193","description":"CWE-193: Off-by-one Error","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:62d6b8ceeea43038b1551df8ee0ce83717c60b8a14208055be69d7bb63cc8eb9 · sha256:897ba3ffd040c3a5… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3xpj-m4hx-8vmx","tags":["x_refsource_CONFIRM"],"url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3xpj-m4hx-8vmx"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:62d6b8ceeea43038b1551df8ee0ce83717c60b8a14208055be69d7bb63cc8eb9 · sha256:897ba3ffd040c3a5… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3xpj-m4hx-8vmx"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:62d6b8ceeea43038b1551df8ee0ce83717c60b8a14208055be69d7bb63cc8eb9 · sha256:897ba3ffd040c3a5… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.