Skip to main content
Vulnerability Database/CVE-2026-95626

CVE-2026-95626: Tauri Framework XSS Vulnerability

CVE-2026-95626 is a cross-site scripting vulnerability in Tauri Framework affecting Content Security Policy protections. Attackers can bypass nonce restrictions using data: or blob: schemes. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2026-95626 Overview

CVE-2026-95626 affects the Tauri application framework's Content Security Policy (CSP) hardening feature. Tauri injects a random nonce into the script-src directive to restrict script execution. This protection fails when an application also includes data: or blob: scheme sources in the same directive. Per the CSP Level 3 specification, scheme sources remain active even when a nonce is present, letting attackers execute arbitrary scripts without knowing the nonce value. The flaw is classified as Cross-Site Scripting [CWE-79] and enables scope-changing script injection within Tauri-based desktop applications.

Critical Impact

An attacker who can inject markup into a Tauri webview can execute arbitrary JavaScript in the application context, bypassing the CSP nonce protection entirely.

Affected Products

Discovery Timeline

  • 2026-09-23 - CVE-2026-95626 published to NVD
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-95626

Vulnerability Analysis

Tauri automatically hardens application CSP headers by generating a per-load random nonce and appending it to the script-src directive. Developers expect this nonce to restrict script execution to explicitly authorized inline blocks. The hardening logic does not remove or reject scheme sources such as data: and blob: when they appear alongside the nonce. Under CSP Level 3, scheme sources and nonces are additive rather than restrictive, meaning any script loaded from a data: URI or blob: URL passes the policy check without the nonce.

The practical impact is that an attacker with any HTML injection primitive inside the webview can inject a <script src="data:..."> tag and execute arbitrary code. In a Tauri context, this JavaScript can reach exposed Rust commands through the IPC bridge, escalating a webview XSS into host code execution.

Root Cause

The root cause is an unsafe interaction between Tauri's CSP hardening and permissive developer-supplied CSP directives. The framework treats the presence of a nonce as sufficient script control and does not warn or strip conflicting scheme sources. The vulnerability maps to [CWE-79], Improper Neutralization of Input During Web Page Generation.

Attack Vector

Exploitation requires a Tauri application whose script-src directive contains data: or blob:, plus an existing script or HTML injection sink inside the webview. The attacker delivers a payload that embeds a <script> element referencing a data: URI containing malicious JavaScript. Because the scheme source authorizes the load, the browser executes the script without the nonce. User interaction is required to reach the vulnerable content, consistent with the vector UI:R. Refer to GHSA-6vxm-x265-58qf for full technical details.

// No verified proof-of-concept code has been published.
// See the vendor advisory for exploitation details.

Detection Methods for CVE-2026-95626

Indicators of Compromise

  • Presence of data: or blob: tokens inside the script-src directive of a Tauri application's tauri.conf.json CSP configuration.
  • Webview telemetry showing script execution from data: URIs or blob: URLs that were not authored by the application.
  • Unexpected invocations of Tauri IPC commands originating from dynamically loaded scripts.

Detection Strategies

  • Static analysis of tauri.conf.json and any runtime CSP overrides to flag scheme sources in script-src.
  • Runtime CSP violation reporting endpoints that capture blocked and allowed script loads for later review.
  • Code review of any component that constructs HTML or manipulates the DOM to identify injection sinks reachable by untrusted input.

Monitoring Recommendations

  • Instrument the webview to log every script element load with its source URI and compare against an allowlist.
  • Monitor Tauri IPC command invocations for anomalous callers, argument shapes, or frequency.
  • Track dependency updates to Tauri and rebuild application bundles when the vendor issues a fixed release.

How to Mitigate CVE-2026-95626

Immediate Actions Required

  • Audit every Tauri application's script-src CSP directive and remove data: and blob: scheme sources.
  • Upgrade to the patched Tauri release identified in GHSA-6vxm-x265-58qf.
  • Review webview code paths that render untrusted content and add output encoding at each sink.

Patch Information

Refer to the vendor advisory GHSA-6vxm-x265-58qf and the Tauri App GitHub Repository for fixed versions and release notes. Rebuild and redistribute application bundles after upgrading the Tauri dependency, since the CSP is compiled into the shipped binary.

Workarounds

  • Remove data: and blob: from the script-src directive and rely on the nonce plus explicit host sources only.
  • If blob: script loading is required, isolate that functionality in a separate webview with a minimal privilege set and no exposed IPC commands.
  • Enforce strict input sanitization on any content rendered inside the webview to eliminate injection sinks that could deliver <script src="data:..."> payloads.
bash
# Example hardened tauri.conf.json CSP snippet
# Remove data: and blob: from script-src
# "csp": "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.