OSV 1.4.0 · github-reviewed · 修改于 2026-07-28 22:44
发布时间
2026-07-28 22:44
GitHub 审查时间
2026-07-28 22:44
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/07/GHSA-7wpj-vvmv-pgm8/GHSA-7wpj-vvmv-pgm8.json
@wakaru/cli is vulnerable to arbitrary file write when unpacking a crafted JavaScript bundle with --unpack.
Bundle-controlled module filenames were sanitized before writing extracted modules to the output directory. A crafted filename containing overlapping path traversal characters, such as ....//, could be transformed into ../ after sanitization. This allowed the final output path to escape the intended output directory.
An attacker who can cause a user to run wakaru --unpack on a malicious bundle may be able to write files outside the selected output directory. Depending on the target path and user environment, this may lead to code execution.
Affected versions: >=1.0.0 <1.4.0.
The issue has been patched in @wakaru/[email protected].
Users should upgrade to:
npm install @wakaru/cli@latest
or specifically:
npm install @wakaru/[email protected]
Do not run wakaru --unpack on untrusted or unknown bundles with affected versions.
If upgrading immediately is not possible, avoid using `--unpack on files that may be attacker-controlled.