VYPR
Medium severity4.8NVD Advisory· Published Jun 23, 2023· Updated Jun 17, 2026

CVE-2023-34460

CVE-2023-34460

Description

Tauri is a framework for building binaries for all major desktop platforms. The 1.4.0 release includes a regression on the Filesystem scope check for dotfiles on Unix. Previously dotfiles were not implicitly allowed by the glob wildcard scopes (eg. $HOME/*), but a regression was introduced when a configuration option for this behavior was implemented. Only Tauri applications using wildcard scopes in the fs endpoint are affected. The regression has been patched on version 1.4.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
tauricrates.io
>= 1.4.0, < 1.4.11.4.1

Affected products

3
  • Tauri Apps/Tauri2 versions
    cpe:2.3:a:tauri:tauri:1.4.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:tauri:tauri:1.4.0:*:*:*:*:*:*:*
    • (no CPE)range: = 1.4.0
  • ghsa-coords
    Range: >= 1.4.0, < 1.4.1

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.