CVE-2026-82635
Last modified
CVE-2026-82635 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containing path traversal sequences (for example ../Library/LaunchAgents/com.evil.plist) or an absolute path resolves outside ~/Downloads. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containing path traversal sequences (for example ../Library/LaunchAgents/com.evil.plist) or an absolute path resolves outside ~/Downloads. The command then fetches attacker-controlled content from the supplied URL (via Rust HTTP, not the browser) and writes it to that path. A script that can invoke the command can overwrite user-writable files and install persistence (macOS LaunchAgents, Linux autostart, Windows Startup), leading to code execution in the user account. All desktop apps generated from an affected Pake tree expose the same command.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| tw93 | Pake | < 3.13.1 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-82635?
How severe is CVE-2026-82635?
How do I fix CVE-2026-82635?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-82629A vulnerability was determined in jeecgboot jeewx-boot up to…4.7
- CVE-2026-8263A security flaw has been discovered in Tenda AC6 15.03.06.49…9.8
- CVE-2026-82630A vulnerability was identified in PowerJob up to 5.1.2. Impa…7.3
- CVE-2026-82631A security flaw has been discovered in valkey-io valkey 9.1.…2.2
- CVE-2026-82633Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-o…4.3
- CVE-2026-82634Frappe Framework development builds contain an authorization…6.5
- CVE-2026-82636Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS comma…7.9
- CVE-2026-82637browser-use web-ui versions 2.0.0 through 3.0.0 fail to vali…5.3
- CVE-2026-82638jina-ai reader disables its private-address guard outside Go…7.5
- CVE-2026-82639NextChat versions from 2.15.8 through 2.16.1 contain an impr…7.5
- CVE-2026-8264A weakness has been identified in Tenda AC6 15.03.06.23. Aff…8.8
- CVE-2026-82640browser-use web-ui versions 2.0.0 through 3.0.0 write config…5.5
Are you affected by CVE-2026-82635?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
