Stackfield Desktop App: RCE via Path Traversal and Arbitrary File Write (CVE-2026-28373)
CVE-2026-28373 describes a path traversal vulnerability in the Stackfield desktop app affecting all versions up to 1.10.1 on Windows and macOS. During the decryption of an encrypted organization data export, attacker-controlled "filePath" and "fileGuid" values are used to derive output locations without proper validation. By crafting a valid encrypted export, a low-privileged attacker can force the app to write arbitrary files outside the export directory, ultimately leading to Remote Code Execution.
Mar 23, 2026