CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-54545

highCVSS 7.1covered by 2 sourcesfirst seen 2026-07-28
Impact @wakaru/cli is vulnerable to arbitrary file write when unpacking a crafted JavaScript bundle with --unpack. Bundle-controlled module filenames were sanitized before writing extracted modules to the output directory. A crafted filename containing overlapping path traversal characters, such as ....//, could be transformed into ../ after sanitization. This allowed the final output path to escape the intended output directory. An attacker who can cause a user to run wakaru --unpack on a malicious bundle may be able to write files outside the selected output directory. Depending on the target path and user environment, this may lead to code execution. Affected versions: >=1.0.0 <1.4.0. Patches The issue has been patched in @wakaru/cli@1.4.0. Users should upgrade to: npm install @wakaru/cli@latest or specifically: npm install @wakaru/cli@1.4.0 Workarounds Do not run wakaru --unpack on untrusted or unknown bundles with affected versions. If upgrading immediately is not possible, avoid using `--unpack on files that may be attacker-controlled.

⚡ Watch CVE-2026-54545

Get an email if CVE-2026-54545 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-54545

CVE.org record

Embed the live status

CVE-2026-54545 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-54545 status](https://www.csirts.com/badge/CVE-2026-54545)](https://www.csirts.com/cve/CVE-2026-54545)