CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-7wpj-vvmv-pgm8: @wakaru/cli arbitrary file write during bundle unpack

highCVSS 7.1CVE-2026-54545
Impact @wakaru/cli is vulnerable to arbitrary file write when unpacking a crafted JavaScript bundle with --unpack. Bundle-controlled module filenames were sanitized before writing extracted modules to the output directory. A crafted filename containing overlapping path traversal characters, such as ....//, could be transformed into ../ after sanitization. This allowed the final output path to escape the intended output directory. An attacker who can cause a user to run wakaru --unpack on a malicious bundle may be able to write files outside the selected output directory. Depending on the target path and user environment, this may lead to code execution. Affected versions: >=1.0.0 <1.4.0. Patches The issue has been patched in @wakaru/cli@1.4.0. Users should upgrade to: npm install @wakaru/cli@latest or specifically: npm install @wakaru/cli@1.4.0 Workarounds Do not run wakaru --unpack on untrusted or unknown bundles with affected versions. If upgrading immediately is not possible, avoid using `--unpack on files that may be attacker-controlled.

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
high — CVSS 7.1
Published
2026-07-28
Last updated
2026-07-28
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-7wpj-vvmv-pgm8

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-54545coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from GitHub Security Advisories