MajorCritical vulnerability
CVE-2026-95626 (CVSS 8.3)
NVD · officialPublished Sep 23, 2026Risk 37/100EPSS 0.3%
Tauri's Content Security Policy hardening, which injects a random nonce to restrict script execution, provides zero protection when an application includes data: or blob: in its script-src directive. Per the CSP Level 3 specification, these scheme sources remain active even when a nonce is present, allowing arbitrary script execution without knowing the nonce.
Technical details
CVSS
8.3
AV:NetworkAC:HighPR:NoneUI:RequiredC:HighI:HighA:High
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source