MinorCritical vulnerability
CVE-2026-95627 (CVSS 7.7)
NVD · officialPublished Sep 23, 2026Risk 23/100EPSS 0.2%
When a Tauri application uses the dialog plugin's file or folder picker, an attacker with JavaScript execution (XSS) can force the scope expansion to be recursive, granting read/write access to an entire directory tree after a single user click on a normal-looking OS file dialog. The user has no indication that recursive access was granted, and the expanded scope cannot be revoked for the lifetime of the application.
Technical details
CVSS
7.7
AV:NetworkAC:HighPR:LowUI:RequiredC:HighI:HighA:None
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source