VYPR
Vendor

Tauri Apps

Products
4
CVEs
15
Across products
18
Status
Private

Products

4

Recent CVEs

15
  • CVE-2025-31477CriApr 2, 2025
    risk 0.57cvss 9.8epss 0.01

    The Tauri shell plugin allows access to the system shell. Prior to 2.2.1, the Tauri shell plugin exposes functionality to execute code and open programs on the system. The open endpoint of this plugin is designed to allow open functionality with the system opener (e.g. xdg-open…

  • CVE-2026-95626HigSep 23, 2026
    risk 0.54cvss 8.3epss 0.00

    Tauri's Content Security Policy hardening, which injects a random nonce to restrict script execution, provides zero protection when an application includes data: or blob: in its script-src directive. Per the CSP Level 3 specification, these scheme sources remain active even when…

  • CVE-2026-95627HigSep 23, 2026
    risk 0.50cvss 7.7epss 0.00

    When a Tauri application uses the dialog plugin's file or folder picker, an attacker with JavaScript execution (XSS) can force the scope expansion to be recursive, granting read/write access to an entire directory tree after a single user click on a normal-looking OS file…

  • CVE-2026-42184HigMay 27, 2026
    risk 0.50cvss 8.8epss 0.00

    Tauri is a framework for building binaries for all major desktop platforms. From 2.0 to 2.11.0, a flaw in Tauri's is_local_url() function causes it to incorrectly classify remote URLs as trusted local origins on Windows and Android. On these systems, Tauri maps custom URI scheme…

  • CVE-2023-46115HigOct 20, 2023
    risk 0.48cvss 8.4epss 0.00

    Tauri is a framework for building binaries for all major desktop platforms. This advisory is not describing a vulnerability in the Tauri code base itself but a commonly used misconfiguration which could lead to leaking of the private key and updater key password into bundled…

  • CVE-2022-39215HigSep 15, 2022
    risk 0.47cvss 8.3epss 0.01

    Tauri is a framework for building binaries for all major desktop platforms. Due to missing canonicalization when `readDir` is called recursively, it was possible to display directory listings outside of the defined `fs` scope. This required a crafted symbolic link or junction…

  • CVE-2026-96454HigSep 23, 2026
    risk 0.46cvss 8.2epss 0.00

    Pake turns a website into a desktop application built on Tauri. Every application it generates inherits two settings from the upstream template, and together they hand native functionality to untrusted web content. The first is in src-tauri/capabilities/default.json, which…

  • CVE-2026-95624MedSep 22, 2026
    risk 0.37cvss 6.8epss 0.00

    The Tauri updater plugin's 'check' IPC command accepts an allowDowngrades boolean parameter directly from frontend JavaScript code. When set to true, it replaces the version comparator from "update must be newer" to "update must be different." Because the default permission set…

  • CVE-2022-46171MedDec 23, 2022
    risk 0.37cvss 6.8epss 0.01

    Tauri is a framework for building binaries for all major desktop platforms. The filesystem glob pattern wildcards `*`, `?`, and `[...]` match file path literals and leading dots by default, which unintentionally exposes sub folder content of allowed paths. Scopes without the…

  • CVE-2026-95625MedSep 23, 2026
    risk 0.31cvss 5.9epss 0.00

    The Tauri updater plugin verifies update binaries using minisign signatures, but the signature covers only the raw binary bytes. The update manifest -- which contains the version number, download URL, and signature -- is fetched over TLS but is never itself signed or…

  • CVE-2024-35222MedMay 23, 2024
    risk 0.31cvss 5.9epss 0.00

    Tauri is a framework for building binaries for all major desktop platforms. Remote origin iFrames in Tauri applications can access the Tauri IPC endpoints without being explicitly allowed in the `dangerousRemoteDomainIpcAccess` in v1 and in the `capabilities` in v2. Valid…

  • CVE-2026-95623MedSep 22, 2026
    risk 0.29cvss 5.6epss 0.00

    The Tauri HTTP plugin validates requested URLs against the application's configured scope allowlist only once, on the initial request. When the remote server responds with an HTTP 3xx redirect, reqwest follows the redirect internally without re-checking the new target URL…

  • CVE-2023-34460MedJun 23, 2023
    risk 0.24cvss 4.8epss 0.01

    Tauri is a framework for building binaries for all major desktop platforms. The 1.4.0 release includes a regression on the Filesystem scope check for dotfiles on Unix. Previously dotfiles were not implicitly allowed by the glob wildcard scopes (eg. `$HOME/*`), but a regression…

  • CVE-2023-31134MedMay 9, 2023
    risk 0.24cvss 4.8epss 0.01

    Tauri is software for building applications for multi-platform deployment. The Tauri IPC is usually strictly isolated from external websites, but in versions 1.0.0 until 1.0.9, 1.1.0 until 1.1.4, and 1.2.0 until 1.2.5, the isolation can be bypassed by redirecting an existing…

  • CVE-2022-41874LowNov 10, 2022
    risk 0.10cvss 2.6epss 0.00

    Tauri is a framework for building binaries for all major desktop platforms. In versions prior to 1.0.7 and 1.1.2, Tauri is vulnerable to an Incorrectly-Resolved Name. Due to incorrect escaping of special characters in paths selected via the file dialog and drag and drop…