VYPR
High severity8.3NVD Advisory· Published Sep 15, 2022· Updated Jun 17, 2026

CVE-2022-39215

CVE-2022-39215

Description

Tauri is a framework for building binaries for all major desktop platforms. Due to missing canonicalization when readDir is called recursively, it was possible to display directory listings outside of the defined fs scope. This required a crafted symbolic link or junction folder inside an allowed path of the fs scope. No arbitrary file content could be leaked. The issue has been resolved in version 1.0.6 and the implementation now properly checks if the requested (sub) directory is a symbolic link outside of the defined scope. Users are advised to upgrade. Users unable to upgrade should disable the readDir endpoint in the allowlist inside the tauri.conf.json.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
tauricrates.io
< 1.0.61.0.6

Affected products

3
  • Tauri Apps/Tauri2 versions
    cpe:2.3:a:tauri:tauri:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:tauri:tauri:*:*:*:*:*:*:*:*range: <1.0.6
    • (no CPE)range: < 1.0.6
  • ghsa-coords
    Range: < 1.0.6

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.