Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
8.8
CVE-2026-82635
- EPSS 0.4%
- Veröffentlicht 30.08.2026 12:26:16
- Zuletzt bearbeitet 04.09.2026 20:32:15
Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containing path traversal sequences (for example ../Library/LaunchAgents/com.evil.plist...
1