CVE-2026-95627EPSS p9.2%

CVE-2026-95627CVE-2026-95627

Description

When a Tauri application uses the dialog plugin's file or folder picker, an attacker with JavaScript execution (XSS) can force the scope expansion to be recursive, granting read/write access to an entire directory tree after a single user click on a normal-looking OS file dialog. The user has no indication that recursive access was granted, and the expanded scope cannot be revoked for the lifetime of the application.

Scoring

CVSS 7.7 ()
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
EPSS0.20% probability of exploitation · percentile 9.2% · 2026-10-05T12:00:23Z
Last modified2026-09-23
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.