<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T08:47:20.888668+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-229327</id>
    <title>EUVD-2026-229327</title>
    <updated>2026-10-03T08:47:20.970708+00:00</updated>
    <content>EUVD-2026-229327</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-229327"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-46171</id>
    <title>fkie_cve-2022-46171</title>
    <updated>2026-10-03T08:47:20.970758+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Tauri is a framework for building binaries for all major desktop platforms. The filesystem glob pattern wildcards `*`, `?`, and `[...]` match file path literals and leading dots by default, which unintentionally exposes sub folder content of allowed paths. Scopes without the wildcards are not affected. As `**` allows for sub directories the behavior there is also as expected. The issue has been patched in the latest release and was backported into the currently supported 1.x branches. There are no known workarounds at the time of publication.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-46171"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6mv3-wm7j-h4w5</id>
    <title>GHSA-6mv3-wm7j-h4w5 — Tauri Filesystem Scope Glob Pattern is too Permissive</title>
    <updated>2026-10-03T08:47:20.970806+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: tauri</p>
<p>### Impact</p>
<p>The filesystem glob pattern wildcards `*`, `?`, and `[...]` match file path literals and leading dots by default, which unintentionally exposes sub folder content of allowed paths.</p>
<p>Example: The `fs` scope `$HOME/*.key` would also allow `$HOME/.ssh/secret.key` to be read even though it is in a sub directory of `$HOME` and is inside a hidden folder.</p>
<p>Scopes without the wildcards are not affected. As `**` allows for sub directories the behavior there is also as expected.</p>
<p>### Patches</p>
<p>The issue has been patched in the latest release and was backported into the currently supported 1.x branches.</p>
<p>### Workarounds</p>
<p>No workaround is known at the time of publication.</p>
<p>### References</p>
<p>The original report contained information that the `dialog.open` component automatically allows one sub directory to be read, regardless of the `recursive` option.</p>
<p>Imagine a file system looking like
```
 o ../
 o documents/
    - file.txt
    - deeper/
       o deep_file.txt
```</p>
<p>Reproduction steps:</p>
<p>1. Trying to load “file.txt” or “deep_file.txt” doesn’t work. Expected
2. Select “documents” as folder to open(ie. with window.__TAURI__.dialog.open)
3. Trying to load “file.txt” works. Expected
5. Trying to load “deep_file.txt” also works, which isn’t expected</p>
<p>The recursive flag is used in https://github.com/tauri-apps/tauri/blob/cd8c074ae6592303d3f6844a4fb6d262eae913b2/core/tauri/src/scope/fs.rs#L154 to scope the filesystem access to either files in the folder or to also include sub director…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6mv3-wm7j-h4w5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-46171</id>
    <title>gsd-2022-46171</title>
    <updated>2026-10-03T08:47:20.970937+00:00</updated>
    <content>gsd-2022-46171</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-46171"/>
  </entry>
</feed>
