Path Traversal Vulnerability in Pake by Tw93
CVE-2026-82635
What is CVE-2026-82635?
The Pake platform prior to version 3.13.1 is susceptible to a path traversal vulnerability through its download_file command. This flaw allows attackers to manipulate JavaScript-supplied filenames, potentially leading to unauthorized access and modifications within user directories. By exploiting this vulnerability, an adversary can fetch malicious content from a designated URL and write it to a specified file path, bypassing security controls. This could result in overwriting critical files and establishing persistence mechanisms, such as macOS LaunchAgents and Windows Startup entries, enabling execution of malicious code within the user's account. It is crucial for users to update to version 3.13.1 or later to mitigate this risk.
Affected Version(s)
Pake 0 < 3.13.1
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
