<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:29:47 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-229327</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-229327</link>
      <description>EUVD-2026-229327</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-229327</guid>
    </item>
    <item>
      <title>fkie_cve-2022-46171</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-46171</link>
      <description>&lt;p&gt;Tauri is a framework for building binaries for all major desktop platforms. The filesystem glob pattern wildcards `*`, `?`, and `[...]` match file path literals and leading dots by default, which unintentionally exposes sub folder content of allowed paths. Scopes without the wildcards are not affected. As `**` allows for sub directories the behavior there is also as expected. The issue has been patched in the latest release and was backported into the currently supported 1.x branches. There are no known workarounds at the time of publication.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Tauri is a framework for building binaries for all major desktop platforms. The filesystem glob pattern wildcards `*`, `?`, and `[...]` match file path literals and leading dots by default, which unintentionally exposes sub folder content of allowed paths. Scopes without the wildcards are not affected. As `**` allows for sub directories the behavior there is also as expected. The issue has been patched in the latest release and was backported into the currently supported 1.x branches. There are no known workarounds at the time of publication.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-46171</guid>
    </item>
    <item>
      <title>GHSA-6mv3-wm7j-h4w5 — Tauri Filesystem Scope Glob Pattern is too Permissive</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6mv3-wm7j-h4w5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: tauri&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The filesystem glob pattern wildcards `*`, `?`, and `[...]` match file path literals and leading dots by default, which unintentionally exposes sub folder content of allowed paths.&lt;/p&gt;
&lt;p&gt;Example: The `fs` scope `$HOME/*.key` would also allow `$HOME/.ssh/secret.key` to be read even though it is in a sub directory of `$HOME` and is inside a hidden folder.&lt;/p&gt;
&lt;p&gt;Scopes without the wildcards are not affected. As `**` allows for sub directories the behavior there is also as expected.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The issue has been patched in the latest release and was backported into the currently supported 1.x branches.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;No workaround is known at the time of publication.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;The original report contained information that the `dialog.open` component automatically allows one sub directory to be read, regardless of the `recursive` option.&lt;/p&gt;
&lt;p&gt;Imagine a file system looking like
```
 o ../
 o documents/
    - file.txt
    - deeper/
       o deep_file.txt
```&lt;/p&gt;
&lt;p&gt;Reproduction steps:&lt;/p&gt;
&lt;p&gt;1. Trying to load “file.txt” or “deep_file.txt” doesn’t work. Expected
2. Select “documents” as folder to open(ie. with window.__TAURI__.dialog.open)
3. Trying to load “file.txt” works. Expected
5. Trying to load “deep_file.txt” also works, which isn’t expected&lt;/p&gt;
&lt;p&gt;The recursive flag is used in https://github.com/tauri-apps/tauri/blob/cd8c074ae6592303d3f6844a4fb6d262eae913b2/core/tauri/src/scope/fs.rs#L154 to scope the filesystem access to either files in the folder or to also include sub director…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: tauri&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The filesystem glob pattern wildcards `*`, `?`, and `[...]` match file path literals and leading dots by default, which unintentionally exposes sub folder content of allowed paths.&lt;/p&gt;
&lt;p&gt;Example: The `fs` scope `$HOME/*.key` would also allow `$HOME/.ssh/secret.key` to be read even though it is in a sub directory of `$HOME` and is inside a hidden folder.&lt;/p&gt;
&lt;p&gt;Scopes without the wildcards are not affected. As `**` allows for sub directories the behavior there is also as expected.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The issue has been patched in the latest release and was backported into the currently supported 1.x branches.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;No workaround is known at the time of publication.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;The original report contained information that the `dialog.open` component automatically allows one sub directory to be read, regardless of the `recursive` option.&lt;/p&gt;
&lt;p&gt;Imagine a file system looking like
```
 o ../
 o documents/
    - file.txt
    - deeper/
       o deep_file.txt
```&lt;/p&gt;
&lt;p&gt;Reproduction steps:&lt;/p&gt;
&lt;p&gt;1. Trying to load “file.txt” or “deep_file.txt” doesn’t work. Expected
2. Select “documents” as folder to open(ie. with window.__TAURI__.dialog.open)
3. Trying to load “file.txt” works. Expected
5. Trying to load “deep_file.txt” also works, which isn’t expected&lt;/p&gt;
&lt;p&gt;The recursive flag is used in https://github.com/tauri-apps/tauri/blob/cd8c074ae6592303d3f6844a4fb6d262eae913b2/core/tauri/src/scope/fs.rs#L154 to scope the filesystem access to either files in the folder or to also include sub director…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6mv3-wm7j-h4w5</guid>
    </item>
    <item>
      <title>gsd-2022-46171</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-46171</link>
      <description>gsd-2022-46171</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-46171</guid>
    </item>
  </channel>
</rss>
