Tag
high
advisory
@wakaru/cli Arbitrary File Write Vulnerability CVE-2026-54545
2 TTPs@wakaru/cli versions from 1.0.0 up to, but not including, 1.4.0 are vulnerable to arbitrary file write due to a path traversal flaw when unpacking a crafted JavaScript bundle using the `--unpack` command, where specially formatted filenames can bypass sanitization and lead to remote code execution.
@wakaru/cli
arbitrary-file-write
path-traversal
code-execution
javascript
cli-tool
2t
critical
advisory
gemini-mcp-tool Vulnerable to OS Command Injection and File Exfiltration (CVE-2026-0755)
2 rules 3 TTPsA critical vulnerability, CVE-2026-0755, in npm's gemini-mcp-tool package allows for OS command injection on Windows systems due to improper handling of unquoted cmd.exe metacharacters, and arbitrary local file exfiltration via the @file parser when processing untrusted prompt input, leading to potential remote code execution and sensitive data compromise.
gemini-mcp-tool
command-injection
file-exfiltration
npm
cli-tool
web-vulnerability
2r
3t