Feed/CVE-2026-54545
CVE-2026-54545HIGHCVSS 7.1

@wakaru/cli arbitrary file write during bundle unpack

Published Jul 28, 2026·Updated Jul 28, 2026

NVD Description

### Impact `@wakaru/cli` is vulnerable to arbitrary file write when unpacking a crafted JavaScript bundle with `--unpack`. Bundle-controlled module filenames were sanitized before writing extracted modules to the output directory. A crafted filename containing overlapping path traversal characters, such as `....//`, could be transformed into `../` after sanitization. This allowed the final output path to escape the intended output directory. An attacker who can cause a user to run `wakaru --unpack` on a malicious bundle may be able to write files outside the selected output directory. Depending on the target path and user environment, this may lead to code execution. Affected versions: `>=1.0.0 <1.4.0`. ### Patches The issue has been patched in `@wakaru/cli@1.4.0`. Users should upgrade to: ```sh npm install @wakaru/cli@latest ``` or specifically: ``` npm install @wakaru/cli@1.4.0 ``` ### Workarounds Do not run `wakaru --unpack` on untrusted or unknown bundles with affected versions. If upgrading immediately is not possible, avoid using `--unpack on files that may be attacker-controlled.

Affected Packages (1)

@wakaru/cliNPM
From 1.0.0
Fixed in 1.4.0

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free