CVE-2026-28373
stackfield, macos
The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property. A malicious export can write arbitrary content to any path on the victim's filesystem.
- CVSS
- 9.6
- EPSS
- 0.42% 34.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.04