Tauri Updater Plugin Vulnerability in Tauri Framework by Tauri Apps
CVE-2026-95624

6.8MEDIUM

Key Information:

Vendor

Tauri

Vendor
CVE Published:
22 September 2026

What is CVE-2026-95624?

The Tauri Updater Plugin contains a vulnerability where the 'check' IPC command accepts an allowDowngrades boolean parameter directly from frontend JavaScript code. When set to true, this parameter alters the version comparison method, allowing downgrades instead of enforcing an update to a newer version. The default permission settings permit access to this command through the webview, enabling potential exploitation via XSS in the app's frontend. This flaw, particularly when combined with other vulnerabilities, facilitates downgrade attacks without the need to spoof higher version numbers, compromising the integrity of the application's update mechanism.

Affected Version(s)

tauri-plugin-updater 2.8.0 < 2.12.0

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yuval Moravchick
JFrog Security Research
.