« Volver al listado

CVE-2026-95624

Estado: AplazadaMedia (6.8)—

The Tauri updater plugin's 'check' IPC command accepts an allowDowngrades boolean parameter directly from frontend JavaScript code. When set to true, it replaces the version comparator from "update must be newer" to "update must be different." Because the default permission set grants allow-check to the webview, any XSS in the app frontend can invoke this command and bypass the only anti-rollback protection the updater offers. Combined with another bug, this enables downgrade attacks without even needing to fake a higher version number.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

XSS permite invocar comandos IPC del updater (T1203), permitiendo manipulación de actualizaciones y degradación de versiones (T1565.001); potencial acceso elevado si se explotan permisos del webview (T1078.004).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-95624",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-95624",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-22T19:30:03.565802Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "reefs@jfrog.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "reefs@jfrog.com",
      "affectedData": [
        {
          "repo": "git://github.com/tauri-apps/tauri",
          "vendor": "Tauri",
          "product": "tauri-plugin-updater",
          "versions": [
            {
              "status": "affected",
              "version": "2.8.0",
              "lessThan": "2.12.0",
              "versionType": "semver"
            }
          ],
          "packageName": "tauri-plugin-updater",
          "programFiles": [
            "plugins/updater/src/commands.rs",
            "plugins/updater/src/config.rs"
          ],
          "collectionURL": "https://crates.io/crates/tauri-plugin-updater",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-09-22T18:17:36.247",
  "references": [
    {
      "url": "https://github.com/tauri-apps/plugins-workspace/commit/1308bfa399b962b3977c767100a6339d1cbfdd20",
      "source": "reefs@jfrog.com"
    },
    {
      "url": "https://github.com/tauri-apps/plugins-workspace/releases/tag/updater-v2.12.0",
      "source": "reefs@jfrog.com"
    },
    {
      "url": "https://github.com/tauri-apps/tauri",
      "source": "reefs@jfrog.com"
    },
    {
      "url": "https://github.com/tauri-apps/tauri/security/advisories/GHSA-rjc6-5hfg-grp9",
      "source": "reefs@jfrog.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "reefs@jfrog.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Tauri updater plugin's 'check' IPC command accepts an allowDowngrades boolean parameter directly from frontend JavaScript code. When set to true, it replaces the version comparator from \"update must be newer\" to \"update must be different.\" Because the default permission set grants allow-check to the webview, any XSS in the app frontend can invoke this command and bypass the only anti-rollback protection the updater offers. Combined with another bug, this enables downgrade attacks without even needing to fake a higher version number."
    }
  ],
  "lastModified": "2026-09-22T20:17:13.343",
  "sourceIdentifier": "reefs@jfrog.com"
}