Insecure File Access in Tauri Applications via Dialog Plugin
CVE-2026-95627

7.7HIGH

Key Information:

Vendor

Tauri

Vendor
CVE Published:
23 September 2026

What is CVE-2026-95627?

A significant security flaw exists in the Tauri dialog plugin, where the file or folder picker can be manipulated by an attacker who can execute JavaScript. This vulnerability allows the attacker to expand the access scope recursively upon a user's interaction with a seemingly benign file dialog. Once activated, this recursive access to an entire directory tree remains granted throughout the application's lifetime, without any alerts to the user about the unauthorized access, thereby posing severe risks to user data and privacy.

Affected Version(s)

tauri-plugin-dialog 2.0.0

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yuval Moravchick
JFrog Security Research
.