Vulnerabilities/

Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`

Severity:
High

Description

The Tauri shell plugin exposes functionality to execute code and open programs on the system. The open endpoint of this plugin is designed to allow open functionality with the system opener (e.g. xdg-open on Linux). This was meant to be restricted to a reasonable number of protocols like https or mailto by default.

Recommendation

Update the @tauri-apps/plugin-shell package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@tauri-apps/plugin-shell
Anything's wrong? Let us know Last updated on April 03, 2025