Executive brief
Tauri's desktop and mobile application framework uses Content Security Policy with random nonces to prevent unauthorized script execution. However, when an application includes data: or blob: URIs in its script-src directive, the nonce protection is completely ineffective, allowing attackers to inject and execute arbitrary scripts. This could lead to full application compromise including data theft, keylogging, or malware installation.
Technical details
Tauri injects random nonces into CSP headers to restrict script execution, but per CSP Level 3 specification, scheme sources like data: and blob: bypass nonce validation and remain active. An attacker who can control data: or blob: URIs in the application's script-src directive can execute arbitrary JavaScript in the application context without knowledge of the nonce. The vulnerability affects applications with permissive CSP configurations that explicitly allow these schemes.
Affected products
- Tauri Tauri <UNKNOWN>
Timeline
- 2026-09-23: disclosed