CVE-2022-41874

Tauri Filesystem Scope can be Partially Bypassed

Description

Tauri is a framework for building binaries for all major desktop platforms. In versions prior to 1.0.7 and 1.1.2, Tauri is vulnerable to an Incorrectly-Resolved Name. Due to incorrect escaping of special characters in paths selected via the file dialog and drag and drop functionality, it is possible to partially bypass the `fs` scope definition. It is not possible to traverse into arbitrary paths, as the issue is limited to neighboring files and sub folders of already allowed paths. The impact differs on Windows, MacOS and Linux due to different specifications of valid path characters. This bypass depends on the file picker dialog or dragged files, as user selected paths are automatically added to the allow list at runtime. A successful bypass requires the user to select a pre-existing malicious file or directory during the file picker dialog and an adversary controlled logic to access these files. The issue has been patched in versions 1.0.7, 1.1.2 and 1.2.0. As a workaround, disable the dialog and fileDropEnabled component inside the tauri.conf.json.

Categories

2.6
CVSS
Severity: Low
CVSS 3.1 •
EPSS 0.04%
Third-Party Advisory github.com
Affected: tauri-apps tauri
Published at:
Updated at:

References

Link Tags
https://github.com/tauri-apps/tauri/security/advisories/GHSA-q9wv-22m9-vhqh issue tracking third party advisory patch

Frequently Asked Questions

What is the severity of CVE-2022-41874?
CVE-2022-41874 has been scored as a low severity vulnerability.
How to fix CVE-2022-41874?
To fix CVE-2022-41874, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2022-41874 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2022-41874 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2022-41874?
CVE-2022-41874 affects tauri-apps tauri.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.