Executive brief
Tauri is a framework for building desktop applications with web technologies. When a Tauri app uses the dialog plugin's file or folder picker, an attacker who gains JavaScript execution (such as through XSS) can trick users into granting recursive read/write access to entire directory trees with a single click on a normal file dialog. Users receive no warning that expanded access was granted and cannot revoke it for the application's lifetime, potentially exposing sensitive files.
Technical details
The vulnerability exists in Tauri's dialog plugin when handling file or folder picker scopes. An attacker with JavaScript execution in the application context can manipulate the scope expansion logic to become recursive, escalating a user-authorized access grant from a single directory to all subdirectories. The attack requires XSS (or equivalent JavaScript execution) as a precondition, but the resulting scope expansion is persistent and cannot be revoked at runtime.
Affected products
- Tauri dialog plugin <UNKNOWN>
Timeline
- 2026-09-23: disclosed