HIGH
tw93
CVE published 2026-08-30
CVE-2026-82635
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-30T13:16:56.923Z and has not been modified since then. Pake before version 3.13.1 has a vulnerability allowing code execution via path traversal in the download_file Tauri command. This command joins the JavaScript-supplied filename for the download onto the user's Downloads directory with no saniti [truncated]