CVE-2026-96454 Overview
Pake converts websites into desktop applications using the Tauri framework. A missing authorization flaw [CWE-862] in the default Pake template exposes native application commands to any HTTPS origin loaded inside the wrapper. The src-tauri/capabilities/default.json file grants inter-process communication (IPC) access with a "remote": { "urls": ["https://*.*"] } wildcard, and "withGlobalTauri": true in src-tauri/tauri.conf.json exposes window.__TAURI__.core.invoke() to page JavaScript. Any script running inside a Pake application can invoke registered app commands, including third-party analytics, advertising, or compromised content delivery network (CDN) scripts.
Critical Impact
Untrusted web content can invoke native application commands. When chained with the path traversal in download_file tracked as CVE-2026-82635, attackers achieve arbitrary file write and persistent code execution.
Affected Products
- Pake desktop application wrapper (upstream template)
- Applications generated from the Pake template prior to release V3.17.0
- Downstream Pake-based binaries distributed to end users
Discovery Timeline
- 2026-09-23 - CVE-2026-96454 published to the National Vulnerability Database (NVD)
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-96454
Vulnerability Analysis
The flaw stems from an overly permissive Tauri capability combined with an access control gap in Tauri's IPC design. The default.json capability file allows any HTTPS origin to issue IPC calls, not only the site the application wraps. The withGlobalTauri flag then injects the __TAURI__ object into every page context, giving ordinary page scripts direct access to invoke().
Tauri's access control list (ACL) enforces permission checks only against plugin commands prefixed with plugin:. Commands registered by the application itself through generate_handler!, known as app commands, bypass the ACL entirely. Pake registers download_file as an app command, so it never appears in the permissions list because permission checks do not apply to it.
Root Cause
The root cause is missing authorization on application-registered Tauri commands combined with a wildcard remote origin allow-list. The upstream template grants IPC to any HTTPS site while the framework applies ACL checks only to plugin commands, leaving app commands reachable without validation.
Attack Vector
Exploitation requires user interaction to launch the Pake application and load an HTTPS page. Once loaded, any JavaScript executing in the page context, including third-party scripts, can call window.__TAURI__.core.invoke('download_file', ...) to reach native functionality. A compromised advertising network, analytics provider, or CDN can trigger the call without the wrapped site's cooperation. Refer to the Tauri Security Capabilities Overview and the Pake capabilities file for the affected configuration.
No verified exploit code is published. The vulnerability is described in prose;
see the Pake repository and Tauri security documentation for configuration details.
Detection Methods for CVE-2026-96454
Indicators of Compromise
- Unexpected files written to disk by a Pake-based application, particularly under user profile or startup directories
- Outbound network requests initiated by a Pake application to origins unrelated to the wrapped site
- Third-party script loads inside a Pake window that reference window.__TAURI__ or call core.invoke
Detection Strategies
- Inspect installed Pake application bundles for "remote": { "urls": ["https://*.*"] } in src-tauri/capabilities/default.json and "withGlobalTauri": true in src-tauri/tauri.conf.json
- Enumerate registered app commands through generate_handler! and confirm each has an equivalent ACL-enforced permission
- Monitor process trees for Pake binaries spawning child processes or writing to sensitive paths such as autostart or shell configuration files
Monitoring Recommendations
- Log file system writes performed by Pake application processes, focusing on locations used for persistence
- Alert on Pake application versions predating Pake release V3.17.0 discovered in the environment
- Track network egress from Pake processes to identify connections outside the wrapped site's expected domains
How to Mitigate CVE-2026-96454
Immediate Actions Required
- Upgrade all Pake-generated applications to the patched release and rebuild downstream binaries against the fixed template
- Inventory internal and third-party Pake distributions and remove unmaintained builds
- Restrict end-user installation of Pake applications from untrusted sources until they are rebuilt
Patch Information
The fix is available in Pake release V3.17.0. Developers must regenerate applications with the updated template so the corrected capabilities/default.json and tauri.conf.json ship in the binary. Reference the Pake repository for build instructions.
Workarounds
- Replace the wildcard remote URL in src-tauri/capabilities/default.json with an explicit list of the exact origins the wrapped site requires
- Set "withGlobalTauri": false in src-tauri/tauri.conf.json to remove window.__TAURI__ from page contexts
- Register sensitive functionality such as download_file as Tauri plugin commands so ACL checks apply, or remove the command entirely if unused
- Rebuild and redistribute affected applications after applying the configuration changes
# Example capability restriction in src-tauri/capabilities/default.json
# Replace the wildcard with the specific wrapped origin
{
"identifier": "default",
"windows": ["main"],
"remote": {
"urls": ["https://your-wrapped-site.example.com"]
},
"permissions": []
}
# In src-tauri/tauri.conf.json, disable global Tauri injection
{
"app": {
"withGlobalTauri": false
}
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
