Executive brief
Pake is a tool that converts web pages into desktop applications. The download_file command fails to properly validate user-supplied filenames, allowing attackers to write files outside the Downloads directory. An attacker can exploit this to overwrite critical system files or install malicious startup scripts that execute automatically when the user logs in, gaining persistent control of the system.
Technical details
The vulnerability is a path traversal flaw in the download_file Tauri command. The root cause is improper filename sanitization: user-controlled filenames containing sequences like "../" or absolute paths are joined directly to the Downloads directory path without validation. The attack vector is JavaScript running within a Pake-generated application; no additional authentication is required if the script has access to the download_file command. An attacker can craft a malicious web page or inject JavaScript into a legitimate app to trigger downloads with traversal payloads (e.g., "../../../Library/LaunchAgents/com.evil.plist" on macOS), causing the Rust HTTP backend to fetch attacker-controlled content and write it to arbitrary user-writable locations. This leads to arbitrary file write, privilege is the user's account, and persistence installation via LaunchAgents (macOS), autostart (Linux), or Startup folders (Windows). A fix sanitizing filenames to use only the final path segment was committed (commit a5463a8).
Affected products
- Pake Pake before 3.13.1
Timeline
- 2026-08-30: disclosed
- 2026-08-30: patched: Fix committed in commit a5463a8 sanitizing download filenames