Skip to main content
Vulnerability Database/CVE-2026-95624

CVE-2026-95624: Tauri Updater Auth Bypass Vulnerability

CVE-2026-95624 is an authentication bypass flaw in Tauri updater plugin that allows attackers to perform downgrade attacks via XSS exploitation. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-95624 Overview

CVE-2026-95624 is an improper access control vulnerability [CWE-284] in the Tauri updater plugin. The check inter-process communication (IPC) command accepts an allowDowngrades boolean parameter directly from frontend JavaScript. When set to true, the version comparator changes from "update must be newer" to "update must be different," removing the plugin's only anti-rollback protection. The default permission set grants allow-check to the webview, so any cross-site scripting (XSS) flaw in the app frontend can invoke the command and trigger a downgrade to a vulnerable prior release.

Critical Impact

An attacker who achieves XSS in a Tauri application frontend can force the updater to install an older, vulnerable version of the application, bypassing rollback protection.

Affected Products

  • Tauri updater plugin (@tauri-apps/plugin-updater) prior to updater-v2.12.0
  • Applications built on the Tauri framework using the default updater permission set
  • Tauri desktop applications exposing the allow-check capability to the webview

Discovery Timeline

  • 2026-09-22 - CVE-2026-95624 published to the National Vulnerability Database (NVD)
  • 2026-09-22 - Last updated in NVD database

Technical Details for CVE-2026-95624

Vulnerability Analysis

The Tauri updater plugin exposes an IPC command named check that Rust code handles in plugins/updater/src/commands.rs. The command signature accepted an allow_downgrades: Option<bool> parameter forwarded directly from the frontend TypeScript binding in plugins/updater/guest-js/index.ts. When the frontend passed true, the updater builder switched its version comparison logic so any target version distinct from the current one qualified as a valid update. The default permission bundle for the plugin included allow-check, so any JavaScript context inside the webview could invoke this command without further authorization.

Root Cause

The root cause is a trust boundary violation. The updater treated a security-sensitive policy control (whether downgrades are permitted) as untrusted user data supplied by the webview. A security decision that should be enforced by the Rust backend or a signed update manifest was delegated to frontend JavaScript, which is the least trustworthy tier of a Tauri application.

Attack Vector

An attacker first needs an XSS foothold or another script-injection vector inside the Tauri application's frontend. From that context, the attacker calls the check command with allowDowngrades: true, then triggers installation of an older signed release that still passes signature validation but contains known exploitable defects. Combined with a separate flaw referenced in the advisory, a downgrade can proceed without needing to forge a higher version number.

typescript
// Patch: removal of the allowDowngrades option from the frontend binding
// File: plugins/updater/guest-js/index.ts
   * Target identifier for the running application. This is sent to the backend.
   */
  target?: string
-  /**
-   * Allow downgrades to previous versions by not checking if the current version is greater than the available version.
-   */
-  allowDowngrades?: boolean
 }

/** Options used when downloading an update */
// Source: https://github.com/tauri-apps/plugins-workspace/commit/1308bfa399b962b3977c767100a6339d1cbfdd20
rust
// Patch: removal of the allow_downgrades parameter from the Rust IPC command
// File: plugins/updater/src/commands.rs
    timeout: Option<u64>,
    proxy: Option<String>,
    target: Option<String>,
-   allow_downgrades: Option<bool>,
) -> Result<Option<Metadata>> {
    let mut builder = webview.updater_builder();
    if let Some(headers) = headers {
// Source: https://github.com/tauri-apps/plugins-workspace/commit/1308bfa399b962b3977c767100a6339d1cbfdd20

Detection Methods for CVE-2026-95624

Indicators of Compromise

  • Application version numbers that regress between telemetry events for the same host and user
  • Updater log entries showing an installed version older than the previously reported running version
  • Outbound requests from the updater to unexpected or non-canonical update manifest endpoints

Detection Strategies

  • Inventory Tauri applications and their bundled @tauri-apps/plugin-updater version through software composition analysis
  • Alert when an endpoint reports an installed application build lower than a prior known-good build
  • Review capability configuration files in Tauri projects for entries granting updater:allow-check broadly to the webview

Monitoring Recommendations

  • Forward application update events into a centralized log store and correlate on version regressions per device
  • Monitor frontend telemetry and content security policy (CSP) violations for signals of XSS activity in Tauri apps
  • Track network calls from Tauri applications to update servers and flag manifests advertising a lower semver than the current release

How to Mitigate CVE-2026-95624

Immediate Actions Required

  • Upgrade the Tauri updater plugin to updater-v2.12.0 or later and rebuild affected applications
  • Rotate application signing keys if there is evidence that a downgrade attack succeeded
  • Audit frontend code for XSS sinks, including any use of innerHTML, template rendering with unsanitized input, or dynamic script loading

Patch Information

The fix is available in Tauri updater plugin v2.12.0. The patch removes the allowDowngrades field from the TypeScript binding and the allow_downgrades argument from the Rust check command, eliminating frontend control over downgrade behavior. See the GitHub Security Advisory GHSA-rjc6-5hfg-grp9 and the remediation commit for details.

Workarounds

  • Restrict the updater capability so allow-check is not granted to webview contexts that render untrusted or user-influenced content
  • Enforce a strict Content Security Policy in the Tauri configuration to reduce the likelihood of XSS execution
  • Host update manifests on infrastructure that only advertises versions greater than or equal to the current release
bash
# Update the Tauri updater plugin in an application project
npm install @tauri-apps/plugin-updater@^2.12.0
cargo update -p tauri-plugin-updater

# Rebuild and re-sign the application bundle
npm run tauri build

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.