---
id: CVE-2026-82635
title: >-
  Pake before 3.13.1 joins the JavaScript-supplied filename for the
  download_file Tauri command onto the user's Downloads directory with no
  sanitization
summary: >-
  Pake before 3.13.1 joins the JavaScript-supplied filename for the
  download_file Tauri command onto the user's Downloads directory with no
  sanitization. A filename containing path traversal sequences (for example
  ../Library/LaunchAgents/c…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
published: '2026-08-30'
updated: '2026-08-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82635'
references:
  - url: 'https://github.com/tw93/Pake'
    label: reefs@jfrog.com
  - url: >-
      https://github.com/tw93/Pake/commit/a5463a84d6e36705ee0dd1886cf0e4b5a75b0ab4
    label: reefs@jfrog.com
  - url: 'https://github.com/tw93/Pake/releases/tag/V3.13.1'
    label: reefs@jfrog.com
tags:
  - nvd
ingestedAt: '2026-08-30T23:59:27.882Z'
epss: 0.0063
epssPercentile: 0.48107
---

## Overview

Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containing path traversal sequences (for example ../Library/LaunchAgents/com.evil.plist) or an absolute path resolves outside ~/Downloads. The command then fetches attacker-controlled content from the supplied URL (via Rust HTTP, not the browser) and writes it to that path. A script that can invoke the command can overwrite user-writable files and install persistence (macOS LaunchAgents, Linux autostart, Windows Startup), leading to code execution in the user account. All desktop apps generated from an affected Pake tree expose the same command.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
