Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-41874

19
FAUCET Score

CVE-2022-41874 is a medium-severity vulnerability affecting Tauri versions prior to 1.0.7 and 1.1.2, allowing for a partial bypass of file system scope definitions. This "Incorrectly-Resolved Name" issue stems from improper escaping of special characters in paths selected via file dialogs or drag-and-drop. Exploitation requires user interaction to select a malicious file or directory, enabling an attacker to access neighboring files and subfolders of already permitted paths. While not actively exploited and lacking public exploit code, the vulnerability has been patched in newer versions, and disabling dialog and fileDropEnabled components serves as a workaround.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.0, < 1.0.7CPE matchmatch criteria
cpe:2.3:a:tauri:tauri:*:*:*:*:*:*:*:*
>= 1.1.0, < 1.1.2CPE matchmatch criteria
cpe:2.3:a:tauri:tauri:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

2.6LOW

CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N

Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
0.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.42%
Probability of exploitation in next 30 days
EPSS Percentile
34.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0042 is in the 36th percentile among its peer group of 26,219 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

github_advisorypatch availablevia nvd_reference
View patch
rustpatch availablevia ghsa
Product: TauriFixed in: 1.0.7
rustpatch availablevia ghsa
Product: TauriFixed in: 1.1.2

Vendor Advisories (1)

rustGHSA-q9wv-22m9-vhqhlow

Tauri Filesystem Scope can be Partially Bypassed

Nov 8, 2022

References

github.com / tauri-apps/tauri/security/advisories/GHSA-q9wv-22m9-vhqh
Issue TrackingPatchThird Party Advisory