Junglewise Threat Intelligence

CVE-2026-96454: Pake arbitrary IPC command execution via wildcard origin validation

CVE-2026-96454 · Severity: high · CVSS 8.2 · Published 2026-09-23

Executive brief

Pake is a tool that wraps websites into desktop applications using Tauri. Every Pake-generated application inherits insecure IPC (inter-process communication) settings that allow any script on any HTTPS website to invoke native commands, including file operations. An attacker can exploit third-party scripts loaded by the wrapped website—such as analytics or advertising—to execute arbitrary native code with the privileges of the desktop application.

Technical details

The vulnerability stems from two inherited configuration settings: a wildcard IPC origin allowlist in capabilities/default.json ("remote": { "urls": ["https://*.*"] }) and global Tauri API exposure via withGlobalTauri set to true. Because Tauri's ACL only enforces plugin commands and not app commands registered via generate_handler!, any origin with IPC access can invoke all app commands, including download_file, without restriction. Combined with CVE-2026-82635 (path traversal in download_file), this enables arbitrary file write and code execution.

Affected products

  • Pake Pake

Timeline

  • 2026-09-23: disclosed