Search

Find a vulnerability

Search criteria

    6 vulnerabilities by tauri

    CVE-2026-95627 (GCVE-0-2026-95627)

    Vulnerability from cvelistv5 – Published: 2026-09-23 09:43 – Updated: 2026-09-23 14:22
    VLAI
    Title
    Tauri framework v2 Dialog plugin auto-expands the filesystem scope with attacker-controlled recursion
    Summary
    When a Tauri application uses the dialog plugin's file or folder picker, an attacker with JavaScript execution (XSS) can force the scope expansion to be recursive, granting read/write access to an entire directory tree after a single user click on a normal-looking OS file dialog. The user has no indication that recursive access was granted, and the expanded scope cannot be revoked for the lifetime of the application.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-23 14:21 UTC
    CWE
    • CWE-732 - Incorrect Permission Assignment for Critical Resource
    Impacted products
    Vendor Product Version
    Tauri tauri-plugin-dialog Affected: 2.0.0 , ≤ * (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-95627",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-23T14:21:31.658846Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-23T14:22:55.260Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://crates.io/crates/tauri-plugin-dialog",
              "defaultStatus": "unaffected",
              "packageName": "tauri-plugin-dialog",
              "product": "tauri-plugin-dialog",
              "programFiles": [
                "plugins/dialog/src/commands.rs"
              ],
              "repo": "git://github.com/tauri-apps/plugins-workspace",
              "vendor": "Tauri",
              "versions": [
                {
                  "lessThanOrEqual": "*",
                  "status": "affected",
                  "version": "2.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Yuval Moravchick"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "JFrog Security Research"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eWhen a Tauri application uses the dialog plugin\u0027s file or folder picker, an attacker with JavaScript execution (XSS) can force the scope expansion to be recursive, granting read/write access to an entire directory tree after a single user click on a normal-looking OS file dialog. The user has no indication that recursive access was granted, and the expanded scope cannot be revoked for the lifetime of the application.\u003c/p\u003e"
                }
              ],
              "value": "When a Tauri application uses the dialog plugin\u0027s file or folder picker, an attacker with JavaScript execution (XSS) can force the scope expansion to be recursive, granting read/write access to an entire directory tree after a single user click on a normal-looking OS file dialog. The user has no indication that recursive access was granted, and the expanded scope cannot be revoked for the lifetime of the application."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Script in the webview gets read and write access to a whole directory tree, after one click on a dialog that looked completely normal. Aim it at the home folder and that is everything the user owns. The script does not need any privileges of its own to ask; an XSS in content the app renders is enough."
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.7,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-732",
                  "description": "CWE-732: Incorrect Permission Assignment for Critical Resource",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-23T09:43:04.542Z",
            "orgId": "48a46f29-ae42-4e1d-90dd-c1676c1e5e6d",
            "shortName": "JFROG"
          },
          "references": [
            {
              "name": "GHSA-vw89-89jm-wmqc (tauri-apps/plugins-workspace)",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/tauri-apps/plugins-workspace/security/advisories/GHSA-vw89-89jm-wmqc"
            },
            {
              "name": "tauri-apps/plugins-workspace repository",
              "tags": [
                "product"
              ],
              "url": "https://github.com/tauri-apps/plugins-workspace"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\u003cspan\u003eThe fix is to stop taking the recursion flag from the caller. Grant what was actually chosen: the one file, or the one folder and nothing below it. An app that genuinely needs a recursive grant can ask for one in its own Rust code, where the frontend cannot reach it.\u003c/span\u003e\u003c/p\u003e"
                }
              ],
              "value": "The fix is to stop taking the recursion flag from the caller. Grant what was actually chosen: the one file, or the one folder and nothing below it. An app that genuinely needs a recursive grant can ask for one in its own Rust code, where the frontend cannot reach it."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2026-06-28T08:23:00.000Z",
              "value": "Reported to the Tauri team as GHSA-vw89-89jm-wmqc"
            }
          ],
          "title": "Tauri framework v2 Dialog plugin auto-expands the filesystem scope with attacker-controlled recursion",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "48a46f29-ae42-4e1d-90dd-c1676c1e5e6d",
        "assignerShortName": "JFROG",
        "cveId": "CVE-2026-95627",
        "datePublished": "2026-09-23T09:43:04.542Z",
        "dateReserved": "2026-09-22T10:38:03.883Z",
        "dateUpdated": "2026-09-23T14:22:55.260Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-95626 (GCVE-0-2026-95626)

    Vulnerability from cvelistv5 – Published: 2026-09-23 09:33 – Updated: 2026-09-23 14:03
    VLAI
    Title
    Tauri framework v2 CSP nonce protection bypass via data and blob URI schemes allows an XSS to RCE chains
    Summary
    Tauri's Content Security Policy hardening, which injects a random nonce to restrict script execution, provides zero protection when an application includes data: or blob: in its script-src directive. Per the CSP Level 3 specification, these scheme sources remain active even when a nonce is present, allowing arbitrary script execution without knowing the nonce.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-23 14:03 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    References
    Impacted products
    Vendor Product Version
    Tauri tauri Affected: 2.0.0 , ≤ * (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-95626",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-23T14:03:10.553800Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-23T14:03:18.426Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://crates.io/crates/tauri",
              "defaultStatus": "unaffected",
              "packageName": "tauri",
              "product": "tauri",
              "programFiles": [
                "crates/tauri-utils/src/html.rs",
                "crates/tauri/src/manager/mod.rs"
              ],
              "repo": "git://github.com/tauri-apps/tauri",
              "vendor": "Tauri",
              "versions": [
                {
                  "lessThanOrEqual": "*",
                  "status": "affected",
                  "version": "2.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Yuval Moravchick"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "JFrog Security Research"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eTauri\u0027s Content Security Policy hardening, which injects a random nonce to restrict script execution, provides zero protection when an application includes data: or blob: in its script-src directive. Per the CSP Level 3 specification, these scheme sources remain active even when a nonce is present, allowing arbitrary script execution without knowing the nonce.\u0026nbsp;\u003c/p\u003e"
                }
              ],
              "value": "Tauri\u0027s Content Security Policy hardening, which injects a random nonce to restrict script execution, provides zero protection when an application includes data: or blob: in its script-src directive. Per the CSP Level 3 specification, these scheme sources remain active even when a nonce is present, allowing arbitrary script execution without knowing the nonce."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.3,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-23T09:33:09.366Z",
            "orgId": "48a46f29-ae42-4e1d-90dd-c1676c1e5e6d",
            "shortName": "JFROG"
          },
          "references": [
            {
              "name": "GHSA-6vxm-x265-58qf (tauri-apps/tauri)",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/tauri-apps/tauri/security/advisories/GHSA-6vxm-x265-58qf"
            },
            {
              "name": "tauri-apps/tauri repository",
              "tags": [
                "product"
              ],
              "url": "https://github.com/tauri-apps/tauri"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2026-06-17T16:46:00.000Z",
              "value": "Reported to the Tauri team as GHSA-6vxm-x265-58qf"
            }
          ],
          "title": "Tauri framework v2 CSP nonce protection bypass via data and blob URI schemes allows an XSS to RCE chains",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "48a46f29-ae42-4e1d-90dd-c1676c1e5e6d",
        "assignerShortName": "JFROG",
        "cveId": "CVE-2026-95626",
        "datePublished": "2026-09-23T09:33:09.366Z",
        "dateReserved": "2026-09-22T10:38:03.883Z",
        "dateUpdated": "2026-09-23T14:03:18.426Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-95625 (GCVE-0-2026-95625)

    Vulnerability from cvelistv5 – Published: 2026-09-23 08:51 – Updated: 2026-09-23 14:10
    VLAI
    Title
    Tauri framework v2 missing updater signature version number validation can be exploited into forced downgrade
    Summary
    The Tauri updater plugin verifies update binaries using minisign signatures, but the signature covers only the raw binary bytes. The update manifest -- which contains the version number, download URL, and signature -- is fetched over TLS but is never itself signed or authenticated. Because the only anti-rollback check compares the manifest's version field against the current version, and that field is unsigned, an attacker who can serve a crafted manifest can force installation of any older signed release without possessing the developer's private key.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-23 14:07 UTC
    CWE
    • CWE-354 - Improper Validation of Integrity Check Value
    Impacted products
    Vendor Product Version
    Tauri tauri-plugin-updater Affected: 2.0.0 , < 2.12.0 (semver)
    Affected: 2.12.0 , ≤ * (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-95625",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-23T14:07:42.715205Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-23T14:10:35.332Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://crates.io/crates/tauri-plugin-updater",
              "defaultStatus": "unaffected",
              "packageName": "tauri-plugin-updater",
              "product": "tauri-plugin-updater",
              "programFiles": [
                "plugins/updater/src/updater.rs",
                "plugins/updater/src/config.rs"
              ],
              "repo": "git://github.com/tauri-apps/plugins-workspace",
              "vendor": "Tauri",
              "versions": [
                {
                  "lessThan": "2.12.0",
                  "status": "affected",
                  "version": "2.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "affected",
                  "version": "2.12.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Yuval Moravchick"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "JFrog Security Research"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe Tauri updater plugin verifies update binaries using minisign signatures, but the signature covers only the raw binary bytes. The update manifest -- which contains the version number, download URL, and signature -- is fetched over TLS but is never itself signed or authenticated. Because the only anti-rollback check compares the manifest\u0027s version field against the current version, and that field is unsigned, an attacker who can serve a crafted manifest can force installation of any older signed release without possessing the developer\u0027s private key.\u003c/p\u003e"
                }
              ],
              "value": "The Tauri updater plugin verifies update binaries using minisign signatures, but the signature covers only the raw binary bytes. The update manifest -- which contains the version number, download URL, and signature -- is fetched over TLS but is never itself signed or authenticated. Because the only anti-rollback check compares the manifest\u0027s version field against the current version, and that field is unsigned, an attacker who can serve a crafted manifest can force installation of any older signed release without possessing the developer\u0027s private key."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-354",
                  "description": "CWE-354: Improper Validation of Integrity Check Value",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-23T08:51:53.922Z",
            "orgId": "48a46f29-ae42-4e1d-90dd-c1676c1e5e6d",
            "shortName": "JFROG"
          },
          "references": [
            {
              "name": "GHSA-j38x-g3m3-95fr (tauri-apps/plugins-workspace)",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/tauri-apps/plugins-workspace/security/advisories/GHSA-j38x-g3m3-95fr"
            },
            {
              "name": "tauri-apps/plugins-workspace repository",
              "tags": [
                "product"
              ],
              "url": "https://github.com/tauri-apps/plugins-workspace"
            },
            {
              "name": "Add requireSignedVersion to bind an update to its signed version",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/tauri-apps/plugins-workspace/commit/690dcfd694"
            },
            {
              "name": "tauri-plugin-updater 2.12.0 release notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/tauri-apps/plugins-workspace/releases/tag/updater-v2.12.0"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eaddressed in tauri-plugin-updater 2.12.0, and it has to be switched on. The new requireSignedVersion option compares the version announced by the endpoint against the version recorded in the signature\u0027s trusted comment, which the signature does cover, and rejects the update when they differ.\u003c/p\u003e"
                }
              ],
              "value": "addressed in tauri-plugin-updater 2.12.0, and it has to be switched on. The new requireSignedVersion option compares the version announced by the endpoint against the version recorded in the signature\u0027s trusted comment, which the signature does cover, and rejects the update when they differ."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-01T13:31:00.000Z",
              "value": "Reported to the Tauri team as GHSA-j38x-g3m3-95fr"
            },
            {
              "lang": "en",
              "time": "2026-09-19T23:57:00.000Z",
              "value": "Opt-in fix released in tauri-plugin-updater 2.12.0, commit 690dcfd694, adding the requireSignedVersion option"
            }
          ],
          "title": "Tauri framework v2 missing updater signature version number validation can be exploited into forced downgrade",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "48a46f29-ae42-4e1d-90dd-c1676c1e5e6d",
        "assignerShortName": "JFROG",
        "cveId": "CVE-2026-95625",
        "datePublished": "2026-09-23T08:51:53.922Z",
        "dateReserved": "2026-09-22T10:38:03.883Z",
        "dateUpdated": "2026-09-23T14:10:35.332Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-95624 (GCVE-0-2026-95624)

    Vulnerability from cvelistv5 – Published: 2026-09-22 17:16 – Updated: 2026-09-22 19:30
    VLAI
    Title
    Tauri framework v2 malicious downgrade via allow_downgrades from frontend code
    Summary
    The Tauri updater plugin's 'check' IPC command accepts an allowDowngrades boolean parameter directly from frontend JavaScript code. When set to true, it replaces the version comparator from "update must be newer" to "update must be different." Because the default permission set grants allow-check to the webview, any XSS in the app frontend can invoke this command and bypass the only anti-rollback protection the updater offers. Combined with another bug, this enables downgrade attacks without even needing to fake a higher version number.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-22 19:30 UTC
    CWE
    • CWE-284 - Improper Access Control
    Impacted products
    Vendor Product Version
    Tauri tauri-plugin-updater Affected: 2.8.0 , < 2.12.0 (semver)
    Create a notification for this product.
    Date Public
    2026-09-23 10:14
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-95624",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-22T19:30:03.565802Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-22T19:30:22.534Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://crates.io/crates/tauri-plugin-updater",
              "defaultStatus": "unaffected",
              "packageName": "tauri-plugin-updater",
              "product": "tauri-plugin-updater",
              "programFiles": [
                "plugins/updater/src/commands.rs",
                "plugins/updater/src/config.rs"
              ],
              "repo": "git://github.com/tauri-apps/tauri",
              "vendor": "Tauri",
              "versions": [
                {
                  "lessThan": "2.12.0",
                  "status": "affected",
                  "version": "2.8.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Yuval Moravchick"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "JFrog Security Research"
            }
          ],
          "datePublic": "2026-09-23T10:14:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe Tauri updater plugin\u0027s \u0027check\u0027 IPC command accepts an allowDowngrades boolean parameter directly from frontend JavaScript code. When set to true, it replaces the version comparator from \"update must be newer\" to \"update must be different.\" Because the default permission set grants allow-check to the webview, any XSS in the app frontend can invoke this command and bypass the only anti-rollback protection the updater offers. Combined with another bug, this enables downgrade attacks without even needing to fake a higher version number.\u003c/p\u003e"
                }
              ],
              "value": "The Tauri updater plugin\u0027s \u0027check\u0027 IPC command accepts an allowDowngrades boolean parameter directly from frontend JavaScript code. When set to true, it replaces the version comparator from \"update must be newer\" to \"update must be different.\" Because the default permission set grants allow-check to the webview, any XSS in the app frontend can invoke this command and bypass the only anti-rollback protection the updater offers. Combined with another bug, this enables downgrade attacks without even needing to fake a higher version number."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.8,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "CWE-284: Improper Access Control",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-22T17:16:25.195Z",
            "orgId": "48a46f29-ae42-4e1d-90dd-c1676c1e5e6d",
            "shortName": "JFROG"
          },
          "references": [
            {
              "name": "GHSA-rjc6-5hfg-grp9 (tauri-apps/tauri)",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/tauri-apps/tauri/security/advisories/GHSA-rjc6-5hfg-grp9"
            },
            {
              "name": "tauri-apps/tauri repository",
              "tags": [
                "product"
              ],
              "url": "https://github.com/tauri-apps/tauri"
            },
            {
              "name": "Move allowDowngrades from the check command to the plugin configuration",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/tauri-apps/plugins-workspace/commit/1308bfa399b962b3977c767100a6339d1cbfdd20"
            },
            {
              "name": "tauri-plugin-updater 2.12.0 release notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/tauri-apps/plugins-workspace/releases/tag/updater-v2.12.0"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eFixed in tauri-plugin-updater 2.12.0. allowDowngrades was removed from the check command and is now read from the plugin configuration instead, where the frontend cannot reach it, and it defaults to false. An application that provides its own version comparator still takes precedence.\u003c/p\u003e"
                }
              ],
              "value": "Fixed in tauri-plugin-updater 2.12.0. allowDowngrades was removed from the check command and is now read from the plugin configuration instead, where the frontend cannot reach it, and it defaults to false. An application that provides its own version comparator still takes precedence."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2026-06-25T09:40:00.000Z",
              "value": "Reported to the Tauri team as GHSA-rjc6-5hfg-grp9"
            },
            {
              "lang": "en",
              "time": "2026-09-20T00:00:00.000Z",
              "value": "Fixed in tauri-plugin-updater 2.12.0, commit 1308bfa399, by moving allowDowngrades out of the IPC command and into the plugin configuration"
            }
          ],
          "title": "Tauri framework v2 malicious downgrade via allow_downgrades from frontend code",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "48a46f29-ae42-4e1d-90dd-c1676c1e5e6d",
        "assignerShortName": "JFROG",
        "cveId": "CVE-2026-95624",
        "datePublished": "2026-09-22T17:16:25.195Z",
        "dateReserved": "2026-09-22T10:38:03.883Z",
        "dateUpdated": "2026-09-22T19:30:22.534Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-95623 (GCVE-0-2026-95623)

    Vulnerability from cvelistv5 – Published: 2026-09-22 10:52 – Updated: 2026-09-22 17:17
    VLAI
    Title
    Tauri framework v2 SSRF Protection Bypass via HTTP Redirects
    Summary
    The Tauri HTTP plugin validates requested URLs against the application's configured scope allowlist only once, on the initial request. When the remote server responds with an HTTP 3xx redirect, reqwest follows the redirect internally without re-checking the new target URL against the scope. This allows an attacker who controls an allowed URL (or finds an open redirect on an allowed host) to reach disallowed destinations such as cloud metadata endpoints, localhost services, or internal network hosts.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-22 12:28 UTC
    CWE
    • CWE-918 - Server-Side Request Forgery (SSRF)
    Impacted products
    Vendor Product Version
    Tauri tauri-plugin-http Affected: 2.0.0 , ≤ 2.6.1 (semver)
    Affected: 2.7.0 , ≤ * (semver)
    Create a notification for this product.
    Date Public
    2026-09-23 10:52
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-95623",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-22T12:28:50.708719Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-22T12:28:59.484Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://crates.io/crates/tauri-plugin-http",
              "defaultStatus": "unaffected",
              "packageName": "tauri-plugin-http",
              "product": "tauri-plugin-http",
              "programFiles": [
                "plugins/http/src/commands.rs",
                "plugins/http/src/scope.rs",
                "plugins/http/src/config.rs"
              ],
              "repo": "git://github.com/tauri-apps/plugins-workspace",
              "vendor": "Tauri",
              "versions": [
                {
                  "lessThanOrEqual": "2.6.1",
                  "status": "affected",
                  "version": "2.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "affected",
                  "version": "2.7.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eVersions 2.0.0 through 2.6.1 are affected in every configuration and no fix is available for them. From 2.7.0 the plugin can check the scope on each redirect hop, but only when the application sets the scopeRedirects option in its http plugin configuration. A 2.7.0 or later application that does not set it behaves as before and is still affected.\u003c/p\u003e"
                }
              ],
              "value": "Versions 2.0.0 through 2.6.1 are affected in every configuration and no fix is available for them. From 2.7.0 the plugin can check the scope on each redirect hop, but only when the application sets the scopeRedirects option in its http plugin configuration. A 2.7.0 or later application that does not set it behaves as before and is still affected."
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Yuval Moravchick"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "JFrog Security Research"
            }
          ],
          "datePublic": "2026-09-23T10:52:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThe Tauri HTTP plugin validates requested URLs against the application\u0027s configured scope allowlist only once, on the initial request. When the remote server responds with an HTTP 3xx redirect, reqwest follows the redirect internally without re-checking the new target URL against the scope. This allows an attacker who controls an allowed URL (or finds an open redirect on an allowed host) to reach disallowed destinations such as cloud metadata endpoints, localhost services, or internal network hosts.\u003c/p\u003e"
                }
              ],
              "value": "The Tauri HTTP plugin validates requested URLs against the application\u0027s configured scope allowlist only once, on the initial request. When the remote server responds with an HTTP 3xx redirect, reqwest follows the redirect internally without re-checking the new target URL against the scope. This allows an attacker who controls an allowed URL (or finds an open redirect on an allowed host) to reach disallowed destinations such as cloud metadata endpoints, localhost services, or internal network hosts."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Requests the frontend starts reach hosts the scope was written to exclude, and the answer is handed back to it. Internal services and cloud metadata endpoints are the obvious targets."
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.6,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "CWE-918: Server-Side Request Forgery (SSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-22T17:17:16.133Z",
            "orgId": "48a46f29-ae42-4e1d-90dd-c1676c1e5e6d",
            "shortName": "JFROG"
          },
          "references": [
            {
              "name": "GHSA-2rxp-f4w5-6hjr (tauri-apps/plugins-workspace)",
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/tauri-apps/plugins-workspace/security/advisories/GHSA-2rxp-f4w5-6hjr"
            },
            {
              "name": "tauri-apps/plugins-workspace repository",
              "tags": [
                "product"
              ],
              "url": "https://github.com/tauri-apps/plugins-workspace"
            },
            {
              "name": "Check the URL scope on every hop of a redirect chain",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/tauri-apps/plugins-workspace/commit/1198a524b710abf2abeb1d9bd7b252402d26ca6d"
            },
            {
              "name": "tauri-plugin-http 2.7.0 release notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/tauri-apps/plugins-workspace/releases/tag/http-v2.7.0"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eUpgrade to tauri-plugin-http 2.7.0 or later and turn on the new scopeRedirects option. Both steps are needed. The fix is opt-in, so 2.7.0 on its own still follows a redirect out of scope; the option is what makes the plugin check every hop. Tauri made it opt-in because a redirect that leaves the scope now fails, which changes behaviour for apps that were relying on it.\u003c/p\u003e\u003ccode\u003e    {\u0026quot;plugins\u0026quot;: {\u0026quot;http\u0026quot;: {\u0026quot;scopeRedirects\u0026quot;: true}}}\u003c/code\u003e\u003cbr/\u003e\u003cp\u003eNothing in the 2.0.0 to 2.6.1 range has a fix available.\u003c/p\u003e"
                }
              ],
              "value": "Upgrade to tauri-plugin-http 2.7.0 or later and turn on the new scopeRedirects option. Both steps are needed. The fix is opt-in, so 2.7.0 on its own still follows a redirect out of scope; the option is what makes the plugin check every hop. Tauri made it opt-in because a redirect that leaves the scope now fails, which changes behaviour for apps that were relying on it.\n\n    {\"plugins\": {\"http\": {\"scopeRedirects\": true}}}\n\n\nNothing in the 2.0.0 to 2.6.1 range has a fix available."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2026-06-28T08:24:00.000Z",
              "value": "Reported to the Tauri team as GHSA-2rxp-f4w5-6hjr"
            },
            {
              "lang": "en",
              "time": "2026-09-20T00:01:00.000Z",
              "value": "Opt-in fix released in tauri-plugin-http 2.7.0, commit 1198a524, adding the scopeRedirects option"
            }
          ],
          "title": "Tauri framework v2 SSRF Protection Bypass via HTTP Redirects",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "48a46f29-ae42-4e1d-90dd-c1676c1e5e6d",
        "assignerShortName": "JFROG",
        "cveId": "CVE-2026-95623",
        "datePublished": "2026-09-22T10:52:20.006Z",
        "dateReserved": "2026-09-22T10:38:03.883Z",
        "dateUpdated": "2026-09-22T17:17:16.133Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-35222 (GCVE-0-2024-35222)

    Vulnerability from cvelistv5 – Published: 2024-05-23 13:20 – Updated: 2024-08-02 03:07
    VLAI
    Title
    iFrames Bypass Origin Checks for Tauri API Access Control
    Summary
    Tauri is a framework for building binaries for all major desktop platforms. Remote origin iFrames in Tauri applications can access the Tauri IPC endpoints without being explicitly allowed in the `dangerousRemoteDomainIpcAccess` in v1 and in the `capabilities` in v2. Valid commands with potentially unwanted consequences ("delete project", "transfer credits", etc.) could be invoked by an attacker that controls the content of an iframe running inside a Tauri app. This vulnerability has been patched in versions 1.6.7 and 2.0.0-beta.19.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-05-23 16:19 UTC
    CWE
    • CWE-284 - Improper Access Control
    References
    Impacted products
    Vendor Product Version
    tauri-apps tauri Affected: <= 1.6.6
    Affected: >= 2.0.0-beta.0, <= 2.0.0-beta.19
    Create a notification for this product.
    tauri tauri Affected: 1.6.6
    Affected: 2.0.0-beta.0 , ≤ 2.0.0-beta.19 (custom)
        cpe:2.3:a:tauri:tauri:1.6.6:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:tauri:tauri:1.6.6:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "tauri",
                "vendor": "tauri",
                "versions": [
                  {
                    "status": "affected",
                    "version": "1.6.6"
                  },
                  {
                    "lessThanOrEqual": "2.0.0-beta.19",
                    "status": "affected",
                    "version": "2.0.0-beta.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-35222",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-05-23T16:19:02.005386Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-04T17:34:02.079Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T03:07:46.872Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "https://github.com/tauri-apps/tauri/security/advisories/GHSA-57fm-592m-34r7",
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://github.com/tauri-apps/tauri/security/advisories/GHSA-57fm-592m-34r7"
              },
              {
                "name": "https://github.com/tauri-apps/tauri/issues/8316",
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://github.com/tauri-apps/tauri/issues/8316"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "tauri",
              "vendor": "tauri-apps",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c= 1.6.6"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 2.0.0-beta.0, \u003c= 2.0.0-beta.19"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Tauri is a framework for building binaries for all major desktop platforms. Remote origin iFrames in Tauri applications can access the Tauri IPC endpoints without being explicitly allowed in the `dangerousRemoteDomainIpcAccess` in v1 and in the `capabilities` in v2. Valid commands with potentially unwanted consequences (\"delete project\", \"transfer credits\", etc.) could be invoked by an attacker that controls the content of an iframe running inside a Tauri app. This vulnerability has been patched in versions 1.6.7 and 2.0.0-beta.19."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "CWE-284: Improper Access Control",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-05-23T13:20:26.220Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/tauri-apps/tauri/security/advisories/GHSA-57fm-592m-34r7",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/tauri-apps/tauri/security/advisories/GHSA-57fm-592m-34r7"
            },
            {
              "name": "https://github.com/tauri-apps/tauri/issues/8316",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/tauri-apps/tauri/issues/8316"
            }
          ],
          "source": {
            "advisory": "GHSA-57fm-592m-34r7",
            "discovery": "UNKNOWN"
          },
          "title": "iFrames Bypass Origin Checks for Tauri API Access Control"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2024-35222",
        "datePublished": "2024-05-23T13:20:26.220Z",
        "dateReserved": "2024-05-14T15:39:41.784Z",
        "dateUpdated": "2024-08-02T03:07:46.872Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }