Junglewise Threat Intelligence

CVE-2026-95626: Tauri Content Security Policy nonce bypass via data and blob schemes

CVE-2026-95626 · Severity: high · CVSS 8.3 · Published 2026-09-23

Vendors: Tauri.

Executive brief

Tauri's desktop and mobile application framework uses Content Security Policy with random nonces to prevent unauthorized script execution. However, when an application includes data: or blob: URIs in its script-src directive, the nonce protection is completely ineffective, allowing attackers to inject and execute arbitrary scripts. This could lead to full application compromise including data theft, keylogging, or malware installation.

Technical details

Tauri injects random nonces into CSP headers to restrict script execution, but per CSP Level 3 specification, scheme sources like data: and blob: bypass nonce validation and remain active. An attacker who can control data: or blob: URIs in the application's script-src directive can execute arbitrary JavaScript in the application context without knowledge of the nonce. The vulnerability affects applications with permissive CSP configurations that explicitly allow these schemes.

Affected products

  • Tauri Tauri <UNKNOWN>

Timeline

  • 2026-09-23: disclosed

References