{"id":"CVE-2026-28373","title":"The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property","summary":"The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property. A malicious export can write arbitrary content to any path …","severity":"critical","cvss":9.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","cwe":["CWE-22"],"vendor":"stackfield","product":"stackfield","affected":["stackfield < 1.10.2"],"patched":["stackfield 1.10.2"],"published":"2026-04-03","updated":"2026-07-24","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-28373","references":[{"url":"https://www.rcesecurity.com/2026/03/stackfield-desktop-app-rce-via-path-traversal-and-arbitrary-file-write-cve-2026-28373/","label":"cve@mitre.org"},{"url":"https://www.rcesecurity.com/advisories/cve-2026-28373/","label":"cve@mitre.org"},{"url":"https://www.stackfield.com/desktop-apps","label":"cve@mitre.org"}],"tags":["nvd"],"epss":0.00587,"epssPercentile":0.4569,"ingestedAt":"2026-07-25T22:05:04.415Z","slug":"CVE-2026-28373","body":"## Overview\n\nThe Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property. A malicious export can write arbitrary content to any path on the victim's filesystem.\n\n## Affected\n\n- `stackfield < 1.10.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `stackfield 1.10.2`","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":52.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}