CVE-2026-95627
7.7 HIGHpublic exploit availablePublished 2026-09-23 · Updated 2026-09-23
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
When a Tauri application uses the dialog plugin's file or folder picker, an attacker with JavaScript execution (XSS) can force the scope expansion to be recursive, granting read/write access to an entire directory tree after a single user click on a normal-looking OS file dialog. The user has no indication that recursive access was granted, and the expanded scope cannot be revoked for the lifetime of the application.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Weaknesses
CWE-732
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-13673
- MEDIUMCVE-2026-15952
- CRITICALCVE-2026-39353PoC
- HIGHCVE-2026-49811
- UNSCOREDCVE-2026-68490
- MEDIUMCVE-2026-76104
- MEDIUMCVE-2026-77256PoC
- MEDIUMCVE-2026-77268PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.