VYPR

Plugins Workspace

by Tauri Apps

Source repositories

CVEs (5)

  • CVE-2025-31477CriApr 2, 2025
    risk 0.57cvss 9.8epss 0.01

    The Tauri shell plugin allows access to the system shell. Prior to 2.2.1, the Tauri shell plugin exposes functionality to execute code and open programs on the system. The open endpoint of this plugin is designed to allow open functionality with the system opener (e.g. xdg-open…

  • CVE-2026-95627HigSep 23, 2026
    risk 0.50cvss 7.7epss 0.00

    When a Tauri application uses the dialog plugin's file or folder picker, an attacker with JavaScript execution (XSS) can force the scope expansion to be recursive, granting read/write access to an entire directory tree after a single user click on a normal-looking OS file…

  • CVE-2026-95624MedSep 22, 2026
    risk 0.37cvss 6.8epss 0.00

    The Tauri updater plugin's 'check' IPC command accepts an allowDowngrades boolean parameter directly from frontend JavaScript code. When set to true, it replaces the version comparator from "update must be newer" to "update must be different." Because the default permission set…

  • CVE-2026-95625MedSep 23, 2026
    risk 0.31cvss 5.9epss 0.00

    The Tauri updater plugin verifies update binaries using minisign signatures, but the signature covers only the raw binary bytes. The update manifest -- which contains the version number, download URL, and signature -- is fetched over TLS but is never itself signed or…

  • CVE-2026-95623MedSep 22, 2026
    risk 0.29cvss 5.6epss 0.00

    The Tauri HTTP plugin validates requested URLs against the application's configured scope allowlist only once, on the initial request. When the remote server responds with an HTTP 3xx redirect, reqwest follows the redirect internally without re-checking the new target URL…