CVE-2022-39215: The readDir Endpoint Scope can be Bypassed With Symbolic Links in Tauri

Published Sep 15, 2022
·
Updated

Tauri is a framework for building binaries for all major desktop platforms. Due to missing canonicalization when readDir is called recursively, it was possible to display directory listings outside of the defined fs scope. This required a crafted symbolic link or junction folder inside an allowed path of the fs scope. No arbitrary file content could be leaked. The issue has been resolved in version 1.0.6 and the implementation now properly checks if the requested (sub) directory is a symbolic link outside of the defined scope. Users are advised to upgrade. Users unable to upgrade should disable the readDir endpoint in the allowlist inside the tauri.conf.json.

Affected Software

1 affected component
Tauri Tauri<1.0.6

Event History

Sep 15, 2022
CVE Published
via MITRE·09:35 PM
Data Sourced
via MITRE·09:35 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is CVE-2022-39215?

CVE-2022-39215 is a vulnerability in the Tauri framework that allows for the display of directory listings outside of the defined fs scope.

2

What is the severity of CVE-2022-39215?

The severity of CVE-2022-39215 is high with a CVSS score of 5.8.

3

How does CVE-2022-39215 affect Tauri?

CVE-2022-39215 affects Tauri versions up to and excluding 1.0.6.

4

How can I fix CVE-2022-39215?

To fix CVE-2022-39215, update Tauri to a version beyond 1.0.6.

5

Where can I find more information about CVE-2022-39215?

You can find more information about CVE-2022-39215 on the Tauri GitHub repository: https://github.com/tauri-apps/tauri/issues/4882

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203