CVE-2022-41874 is a medium-severity vulnerability affecting Tauri versions prior to 1.0.7 and 1.1.2, allowing for a partial bypass of file system scope definitions. This "Incorrectly-Resolved Name" issue stems from improper escaping of special characters in paths selected via file dialogs or drag-and-drop. Exploitation requires user interaction to select a malicious file or directory, enabling an attacker to access neighboring files and subfolders of already permitted paths. While not actively exploited and lacking public exploit code, the vulnerability has been patched in newer versions, and disabling dialog and fileDropEnabled components serves as a workaround.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, < 1.0.7CPE matchmatch criteria | cpe:2.3:a:tauri:tauri:*:*:*:*:*:*:*:* | ||
>= 1.1.0, < 1.1.2CPE matchmatch criteria | cpe:2.3:a:tauri:tauri:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.