๐Ÿ” CVE Alert

CVE-2026-95627

HIGH 7.7

Tauri framework v2 Dialog plugin auto-expands the filesystem scope with attacker-controlled recursion

CVSS Score
7.7
EPSS Score
0.3%
EPSS Percentile
27th

When a Tauri application uses the dialog plugin's file or folder picker, an attacker with JavaScript execution (XSS) can force the scope expansion to be recursive, granting read/write access to an entire directory tree after a single user click on a normal-looking OS file dialog. The user has no indication that recursive access was granted, and the expanded scope cannot be revoked for the lifetime of the application.

CWE CWE-732
Vendor tauri
Product tauri-plugin-dialog
Published Sep 23, 2026
Last Updated Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for tauri tauri-plugin-dialog

Be the first to know when new high vulnerabilities affecting tauri tauri-plugin-dialog are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

Tauri / tauri-plugin-dialog
2.0.0 โ‰ค *

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/tauri-apps/plugins-workspace/security/advisories/GHSA-vw89-89jm-wmqc github.com: https://github.com/tauri-apps/plugins-workspace

Credits

Yuval Moravchick JFrog Security Research