Path Traversal Vulnerability in Pake by Tw93
CVE-2026-82635

8.8HIGH

Key Information:

Vendor

Tw93

Status
Vendor
CVE Published:
30 August 2026

Badges

👾 Exploit Exists

What is CVE-2026-82635?

The Pake platform prior to version 3.13.1 is susceptible to a path traversal vulnerability through its download_file command. This flaw allows attackers to manipulate JavaScript-supplied filenames, potentially leading to unauthorized access and modifications within user directories. By exploiting this vulnerability, an adversary can fetch malicious content from a designated URL and write it to a specified file path, bypassing security controls. This could result in overwriting critical files and establishing persistence mechanisms, such as macOS LaunchAgents and Windows Startup entries, enabling execution of malicious code within the user's account. It is crucial for users to update to version 3.13.1 or later to mitigate this risk.

Affected Version(s)

Pake 0 < 3.13.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yuval Moravchick
JFrog Security Research
.