tauri
crates.io7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting tauripage 1 of 1
- CVE-2022-39215HIGHCVSS 8.3EG 8.3fixed in 1.0.62022-09-15
Tauri is a framework for building binaries for all major desktop platforms. Due to missing canonicalization when `readDir` is called recursively, it was possible to display directory listings outside of the defined `fs` scope. This require…
- CVE-2022-41874LOWCVSS 2.6EG 2.6fixed in 1.0.7 or 1.1.2, by version range2022-11-10
Tauri is a framework for building binaries for all major desktop platforms. In versions prior to 1.0.7 and 1.1.2, Tauri is vulnerable to an Incorrectly-Resolved Name. Due to incorrect escaping of special characters in paths selected via th…
- CVE-2022-46171MEDIUMCVSS 6.8EG 6.8fixed in 1.0.8, 1.1.3, 1.2.3 or 2.0.0-alpha.2, by version range2022-12-23
Tauri is a framework for building binaries for all major desktop platforms. The filesystem glob pattern wildcards `*`, `?`, and `[...]` match file path literals and leading dots by default, which unintentionally exposes sub folder content …
- CVE-2023-31134MEDIUMCVSS 4.8EG 4.8fixed in 1.0.9, 1.1.4 or 1.2.5, by version range2023-05-09
Tauri is software for building applications for multi-platform deployment. The Tauri IPC is usually strictly isolated from external websites, but in versions 1.0.0 until 1.0.9, 1.1.0 until 1.1.4, and 1.2.0 until 1.2.5, the isolation can be…
- CVE-2023-34460MEDIUMCVSS 4.8EG 4.8fixed in 1.4.12023-06-23
vulnerable: 1.4.0
Tauri is a framework for building binaries for all major desktop platforms. The 1.4.0 release includes a regression on the Filesystem scope check for dotfiles on Unix. Previously dotfiles were not implicitly allowed by the glob wildcard sc…
- CVE-2024-35222MEDIUMCVSS 5.9EG 5.9fixed in 1.6.7 or 2.0.0-beta.20, by version range2024-05-23
Tauri is a framework for building binaries for all major desktop platforms. Remote origin iFrames in Tauri applications can access the Tauri IPC endpoints without being explicitly allowed in the `dangerousRemoteDomainIpcAccess` in v1 and i…
- CVE-2026-42184HIGHCVSS 8.8EG 8.8fixed in 2.11.12026-05-27
Tauri is a framework for building binaries for all major desktop platforms. From 2.0 to 2.11.0, a flaw in Tauri's is_local_url() function causes it to incorrectly classify remote URLs as trusted local origins on Windows and Android. On the…
Check whether tauri is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for tauri CVEs against the assets you own.
Book a Demo →