CVE-2026-95627 Details
Description
When a Tauri application uses the dialog plugin's file or folder picker, an attacker with JavaScript execution (XSS) can force the scope expansion to be recursive, granting read/write access to an entire directory tree after a single user click on a normal-looking OS file dialog. The user has no indication that recursive access was granted, and the expanded scope cannot be revoked for the lifetime of the application.
A vulnerability exists in Tauri applications that use the dialog plugin's file or folder picker. An attacker with the ability to execute JavaScript can manipulate the file picker to grant recursive read/write access to an entire directory tree. This is done after a single user click on a seemingly normal file dialog. The user is unaware that such access has been granted, and once the scope is expanded, it cannot be revoked for the duration of the application's runtime.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 23, 2026CISA-ADP
Assessed Sep 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/tauri-apps/plugins-workspace | [email protected] | Vendor |
| https://github.com/tauri-apps/plugins-workspace/security/advisories/GHSA-vw89-89jm-wmqc | [email protected] | AdvisoryBroken LinkVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-732 | Incorrect Permission Assignment for Critical Resource | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Tauri Plugins Workspace | All versions |
CPE
Remediation
| |
| Tauri Plugins Workspace Dialog | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 23, 2026 | CVE Modified | CISA-ADP |
| Sep 23, 2026 | New CVE Received | [email protected] |
Volerion