GHSA-7wpj-vvmv-pgm8HighCVSS 7.1

@wakaru/cli arbitrary file write during bundle unpack

Published
July 28, 2026
Last Modified
July 28, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

@wakaru/cli is vulnerable to arbitrary file write when unpacking a crafted JavaScript bundle with --unpack.

Bundle-controlled module filenames were sanitized before writing extracted modules to the output directory. A crafted filename containing overlapping path traversal characters, such as ....//, could be transformed into ../ after sanitization. This allowed the final output path to escape the intended output directory.

An attacker who can cause a user to run wakaru --unpack on a malicious bundle may be able to write files outside the selected output directory. Depending on the target path and user environment, this may lead to code execution.

Affected versions: >=1.0.0 <1.4.0.

Patches

The issue has been patched in @wakaru/[email protected].

Users should upgrade to:

npm install @wakaru/cli@latest

or specifically:

npm install @wakaru/[email protected]

Workarounds

Do not run wakaru --unpack on untrusted or unknown bundles with affected versions.

If upgrading immediately is not possible, avoid using `--unpack on files that may be attacker-controlled.

🎯 Affected products1

  • npm/@wakaru/cli:>= 1.0.0, < 1.4.0

🔗 References (4)