CVE-2026-95627 Overview
CVE-2026-95627 affects the Tauri dialog plugin used by Tauri desktop applications for native file and folder pickers. An attacker with JavaScript execution in the WebView, typically through Cross-Site Scripting (XSS), can coerce the dialog plugin into recursively expanding the file system scope. A single user click on a normal-looking OS file dialog grants read and write access across the entire selected directory tree.
The user receives no visual indication that recursive access was granted. The expanded scope persists for the lifetime of the application and cannot be revoked. This weakness is classified under CWE-732: Incorrect Permission Assignment for Critical Resource.
Critical Impact
A single user interaction with a native picker can convert a limited XSS foothold into full read/write access over an arbitrary directory tree for the running application.
Affected Products
- Tauri applications using the plugin-dialog file or folder picker
- Tauri Plugins Workspace releases prior to the fixed version referenced in GHSA-vw89-89jm-wmqc
- Desktop applications built on the Tauri framework that expose the dialog plugin to WebView content
Discovery Timeline
- 2026-09-23 - CVE-2026-95627 published to NVD
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-95627
Vulnerability Analysis
Tauri applications sandbox WebView content by defining an allowlist of file system paths the frontend may access. The dialog plugin extends this scope at runtime when the user selects a file or folder through a native OS picker. This runtime expansion is the intended trust boundary between the untrusted WebView and the host file system.
The flaw allows an attacker who already controls JavaScript execution in the WebView to influence the dialog invocation such that the scope added after a user selection is recursive. Instead of granting access only to the chosen file or the immediate folder contents, the plugin registers the entire subtree. The picker UI does not communicate this expansion, so the user believes they authorized access to a single file.
Once the scope is expanded, subsequent file system calls from the WebView succeed against any path beneath the selected directory. Because Tauri scope entries are additive and permanent for the process lifetime, the elevated access cannot be withdrawn without restarting the application.
Root Cause
The root cause is an incorrect permission assignment [CWE-732] in the dialog plugin's scope registration logic. Attacker-controlled parameters passed from the WebView determine whether the resulting scope entry is recursive, without validation against a policy defined by the application author.
Attack Vector
Exploitation requires an existing XSS or equivalent script execution primitive inside the Tauri WebView and a user willing to interact with a native file picker. The attacker triggers the dialog invocation with parameters that request recursive scope expansion. When the user completes a normal selection, the plugin grants the WebView broad file system access, enabling exfiltration or modification of files across the chosen directory tree. Refer to the GitHub Security Advisory GHSA-vw89-89jm-wmqc for the technical description.
Detection Methods for CVE-2026-95627
Indicators of Compromise
- Tauri IPC logs showing dialog plugin invocations followed by file system reads or writes to paths outside the expected working set.
- Unexpected access to files nested several levels below directories a user selected through a picker.
- Application telemetry indicating scope entries added at runtime with recursive flags set.
Detection Strategies
- Audit Tauri application source for calls to the dialog plugin and confirm that recursive scope options are not attacker-influenceable.
- Review the tauri.conf.json capabilities and permissions to identify whether the dialog and fs plugins are exposed together to untrusted content.
- Instrument the WebView to log every dialog invocation with parameters and correlate against subsequent file system plugin calls.
Monitoring Recommendations
- Monitor endpoints running Tauri applications for anomalous file access patterns originating from application processes shortly after dialog interactions.
- Alert on outbound network transfers of files that were not previously part of the application's expected data set.
- Track application version inventory and flag hosts running Tauri dialog plugin versions listed in GHSA-vw89-89jm-wmqc.
How to Mitigate CVE-2026-95627
Immediate Actions Required
- Upgrade the Tauri dialog plugin to the fixed release referenced in GHSA-vw89-89jm-wmqc.
- Rebuild and redistribute affected Tauri applications to end users after upgrading the plugin dependency.
- Audit the application frontend for XSS sinks, since exploitation requires JavaScript execution in the WebView.
Patch Information
The fix is distributed through the Tauri Plugins Workspace repository. Application authors must update the tauri-plugin-dialog dependency to the patched version identified in the advisory and produce a new signed application build. There is no server-side mitigation because Tauri applications ship the plugin binary to the endpoint.
Workarounds
- Restrict the fs plugin scope in tauri.conf.json to specific paths so that scope expansion cannot broaden access beyond a tightly defined allowlist.
- Remove or gate the dialog plugin exposure in application capabilities if native file selection is not required.
- Enforce a strict Content Security Policy on the WebView to reduce the likelihood of the XSS precondition being satisfied.
# Update the dialog plugin to the patched release
cargo update -p tauri-plugin-dialog
npm install @tauri-apps/plugin-dialog@latest
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
