Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade Pake to 3.13.1 or later and rebuild generated apps from that tree. The fix introduces sanitize_download_filename and uses only the final path segment before joining onto the Downloads directory, so ../ and absolute paths cannot escape that directory.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 30 Aug 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containing path traversal sequences (for example ../Library/LaunchAgents/com.evil.plist) or an absolute path resolves outside ~/Downloads. The command then fetches attacker-controlled content from the supplied URL (via Rust HTTP, not the browser) and writes it to that path. A script that can invoke the command can overwrite user-writable files and install persistence (macOS LaunchAgents, Linux autostart, Windows Startup), leading to code execution in the user account. All desktop apps generated from an affected Pake tree expose the same command. | |
| Title | Pake arbitrary file write via unsanitized download_file filename | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: JFROG
Published:
Updated: 2026-08-30T12:26:16.770Z
Reserved: 2026-08-30T12:09:20.896Z
Link: CVE-2026-82635
No data.
Status : Received
Published: 2026-08-30T13:16:56.923
Modified: 2026-08-30T13:16:56.923
Link: CVE-2026-82635
No data.
OpenCVE Enrichment
Updated: 2026-08-30T14:00:15Z