Vulnerability library
Security checkApril 03, 2025

Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

The Tauri shell plugin exposes functionality to execute code and open programs on the system. The open endpoint of this plugin is designed to allow open functionality with the system opener (e.g. xdg-open on Linux). This was meant to be restricted to a reasonable number of protocols like https or mailto by default.

Recommendation

Update the @tauri-apps/plugin-shell package to the latest compatible version. Followings are version details:

  • Affected version(s): < 2.2.1
  • Patched version(s): 2.2.1

References

Could your website be exposed too?

SmartScanner can check your website for Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell` and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated April 03, 2025