VDB
EN
HIGH 7.1

GHSA-7wpj-vvmv-pgm8

@wakaru/cli arbitrary file write during bundle unpack

빠른 조치

GHSA-7wpj-vvmv-pgm8 — @wakaru/cli: 아래 명령으로 수정 버전으로 올리세요.

npm install @wakaru/cli@1.4.0

상세

### Impact

`@wakaru/cli` is vulnerable to arbitrary file write when unpacking a crafted JavaScript bundle with `--unpack`.

Bundle-controlled module filenames were sanitized before writing extracted modules to the output directory. A crafted filename containing overlapping path traversal characters, such as `....//`, could be transformed into `../` after sanitization. This allowed the final output path to escape the intended output directory.

An attacker who can cause a user to run `wakaru --unpack` on a malicious bundle may be able to write files outside the selected output directory. Depending on the target path and user environment, this may lead to code execution.

Affected versions: `>=1.0.0 <1.4.0`.

### Patches

The issue has been patched in `@wakaru/cli@1.4.0`.

Users should upgrade to:

```sh npm install @wakaru/cli@latest ```

or specifically: ``` npm install @wakaru/cli@1.4.0 ```

### Workarounds

Do not run `wakaru --unpack` on untrusted or unknown bundles with affected versions.

If upgrading immediately is not possible, avoid using `--unpack on files that may be attacker-controlled.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / @wakaru/cli
최초 영향 버전: 1.0.0 수정 버전: 1.4.0
수정 npm install @wakaru/cli@1.4.0

참고