{"id":"CVE-2023-34460","summary":"Tauri vulnerable to Regression on Filesystem Scope Checks for Dotfiles","details":"Tauri is a framework for building binaries for all major desktop platforms. The 1.4.0 release includes a regression on the Filesystem scope check for dotfiles on Unix. Previously dotfiles were not implicitly allowed by the glob wildcard scopes (eg. `$HOME/*`), but a regression was introduced when a configuration option for this behavior was implemented. Only Tauri applications using wildcard scopes in the `fs` endpoint are affected. The regression has been patched on version 1.4.1.\n\n","aliases":["GHSA-wmff-grcw-jcfm"],"modified":"2026-09-16T03:30:15.027956666Z","published":"2023-06-23T19:09:54.173Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/34xxx/CVE-2023-34460.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-285"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/34xxx/CVE-2023-34460.json"},{"type":"ADVISORY","url":"https://github.com/tauri-apps/tauri/security/advisories/GHSA-wmff-grcw-jcfm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-34460"},{"type":"FIX","url":"https://github.com/tauri-apps/tauri/commit/066c09a6ea06f42f550d090715e06beb65cd5564"},{"type":"FIX","url":"https://github.com/tauri-apps/tauri/pull/6969#discussion_r1232018347"},{"type":"FIX","url":"https://github.com/tauri-apps/tauri/pull/7227"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tauri-apps/tauri","events":[{"introduced":"b7ae725c5ed569838d1dd48fda80e46e49d7f191"},{"last_affected":"b7ae725c5ed569838d1dd48fda80e46e49d7f191"}],"database_specific":{"extracted_events":[{"introduced":"= 1.4.0"},{"last_affected":"= 1.4.0"}],"source":"AFFECTED_FIELD"}}],"versions":["= 1.4.0","tauri-v1.4.0","tauri-utils-v1.4.0","tauri-utils-v1.4","tauri-runtime-wry-v0.14.0","tauri-runtime-v0.14.0","tauri-macros-v1.4.0","tauri-codegen-v1.4.0","tauri-cli-v1.4.0","tauri-cli-v1.4","tauri-bundler-v1.3.0","tauri-bundler-v1.3","tauri-build-v1.4.0","tauri-build-v1.4","@tauri-apps/cli-v1.4.0","@tauri-apps/api-v1.4.0","@tauri-apps/api-v1.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-34460.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N"}]}