{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/@wakaru/cli--1.4.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@wakaru/cli (\u003c 1.4.0)"],"_cs_severities":["high"],"_cs_tags":["arbitrary-file-write","path-traversal","code-execution","javascript","cli-tool"],"_cs_type":"advisory","_cs_vendors":["Wakaru"],"content_html":"\u003cp\u003eA high-severity arbitrary file write vulnerability, tracked as CVE-2026-54545, has been identified in \u003ccode\u003e@wakaru/cli\u003c/code\u003e versions 1.0.0 through 1.3.x. This flaw allows an attacker to write files outside the intended output directory when a user unpacks a specially crafted JavaScript bundle using the \u003ccode\u003ewakaru --unpack\u003c/code\u003e command. The vulnerability stems from insufficient sanitization of bundle-controlled module filenames, where overlapping path traversal characters (e.g., \u003ccode\u003e....//\u003c/code\u003e) are mishandled, converting to \u003ccode\u003e../\u003c/code\u003e after sanitization. This bypass enables an attacker to escape the designated directory and write malicious files to arbitrary locations on the file system. Depending on the target path and user environment, successful exploitation could lead to code execution, compromising the affected system. Users are strongly advised to upgrade to version 1.4.0 or later to mitigate this risk.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker crafts a malicious JavaScript bundle that includes specially formatted filenames containing overlapping path traversal characters, such as \u003ccode\u003e....//\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe attacker delivers this malicious bundle to a target user, potentially via phishing, untrusted repositories, or compromised distribution channels.\u003c/li\u003e\n\u003cli\u003eThe attacker convinces the user to execute the \u003ccode\u003ewakaru --unpack\u003c/code\u003e command on the malicious bundle using an affected version of \u003ccode\u003e@wakaru/cli\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003e@wakaru/cli\u003c/code\u003e application begins the process of unpacking the bundle and processing its module filenames.\u003c/li\u003e\n\u003cli\u003eDuring the internal sanitization process of bundle-controlled module filenames, the crafted \u003ccode\u003e....//\u003c/code\u003e sequence is improperly handled.\u003c/li\u003e\n\u003cli\u003eThe sanitization logic inadvertently transforms \u003ccode\u003e....//\u003c/code\u003e into \u003ccode\u003e../\u003c/code\u003e, effectively creating an unintended path traversal.\u003c/li\u003e\n\u003cli\u003eAs \u003ccode\u003ewakaru\u003c/code\u003e writes the extracted modules, the arbitrary \u003ccode\u003e../\u003c/code\u003e path component allows files to be written to locations outside the user's specified output directory.\u003c/li\u003e\n\u003cli\u003eDepending on the chosen target path, this arbitrary file write can be used to overwrite critical system files or place malicious executables, potentially leading to code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-54545 results in an arbitrary file write vulnerability. An attacker can place files anywhere on the target system where the user running \u003ccode\u003ewakaru\u003c/code\u003e has write permissions. This could lead to a range of severe consequences, including overwriting legitimate software, deploying persistent malware, or establishing unauthorized access. In many scenarios, an arbitrary file write is a critical precursor to remote code execution (RCE), allowing the attacker to fully compromise the system. The specific impact depends on the files written and their location, but the potential for complete system compromise is significant.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003e@wakaru/cli\u003c/code\u003e to version \u003ccode\u003e1.4.0\u003c/code\u003e or later immediately to patch CVE-2026-54545.\u003c/li\u003e\n\u003cli\u003eAvoid using the \u003ccode\u003ewakaru --unpack\u003c/code\u003e command on untrusted or unknown bundles if immediate upgrade is not possible.\u003c/li\u003e\n\u003cli\u003eImplement strong application whitelisting policies to prevent the execution of unauthorized or newly written executables.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T14:45:07Z","date_published":"2026-07-28T14:45:07Z","id":"https://feed.craftedsignal.io/briefs/2026-07-wakaru-cli-file-write/","summary":"@wakaru/cli versions from 1.0.0 up to, but not including, 1.4.0 are vulnerable to arbitrary file write due to a path traversal flaw when unpacking a crafted JavaScript bundle using the `--unpack` command, where specially formatted filenames can bypass sanitization and lead to remote code execution.","title":"@wakaru/cli Arbitrary File Write Vulnerability CVE-2026-54545","url":"https://feed.craftedsignal.io/briefs/2026-07-wakaru-cli-file-write/"}],"language":"en","title":"CraftedSignal Threat Feed - @Wakaru/Cli (\u003c 1.4.0)","version":"https://jsonfeed.org/version/1.1"}