Tauri is a lightweight framework for building cross-platform desktop applications using web technologies, and its vulnerability footprint centers on its core runtime and plugin ecosystem, particularly the shell-integration plugin. The vendor's disclosures skew toward serious outcomes, with elevated critical-severity representation, and recur through weaknesses including path traversal, improper authorization, exposure of sensitive information, and input-validation gaps that are characteristic of interprocess communication and sandbox-boundary issues inherent to bridging web and native execution contexts. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tauri over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42184HIGH Tauri is a framework for building binaries for all major desktop platforms. From 2.0 to 2.11.0, a flaw in Tauri's is_local_url() function causes it to incorrectly classify remote U | May 27, 2026 | 8.8 | 32 | NO | NO |
CVE-2023-34460CRITICAL Tauri is a framework for building binaries for all major desktop platforms. The 1.4.0 release includes a regression on the Filesystem scope check for dotfiles on Unix. Previously d | Jun 23, 2023 | 9.8 | 29 | NO | NO |
CVE-2025-31477CRITICAL The Tauri shell plugin allows access to the system shell. Prior to 2.2.1, the Tauri shell plugin exposes functionality to execute code and open programs on the system. The open end | Apr 2, 2025 | 9.8 | 28 | NO | NO |
CVE-2022-46171HIGH Tauri is a framework for building binaries for all major desktop platforms. The filesystem glob pattern wildcards `*`, `?`, and `[...]` match file path literals and leading dots by | Dec 23, 2022 | 7.7 | 25 | NO | NO |
CVE-2022-39215MEDIUM Tauri is a framework for building binaries for all major desktop platforms. Due to missing canonicalization when `readDir` is called recursively, it was possible to display directo | Sep 15, 2022 | 5.8 | 21 | NO | NO |
CVE-2023-31134MEDIUM Tauri is software for building applications for multi-platform deployment. The Tauri IPC is usually strictly isolated from external websites, but in versions 1.0.0 until 1.0.9, 1.1 | May 9, 2023 | 5.4 | 19 | NO | NO |
CVE-2022-41874MEDIUM Tauri is a framework for building binaries for all major desktop platforms. In versions prior to 1.0.7 and 1.1.2, Tauri is vulnerable to an Incorrectly-Resolved Name. Due to incorr | Nov 10, 2022 | 4.7 | 19 | NO | NO |
CVE-2023-46115MEDIUM Tauri is a framework for building binaries for all major desktop platforms. This advisory is not describing a vulnerability in the Tauri code base itself but a commonly used miscon | Oct 20, 2023 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tauri.
Media articles that mention a CVE ID that affects a product developed by Tauri — matched by CVE ID, not by vendor name.