tauri is vulnerable to Insecure Direct Object Reference (IDOR)
74
High Risk
Tauri's IPC channel fetch path queues large invoke responses in a single process wide map keyed only by a sequential u32 id, shared across every webview. Any webview can call the internal fetch-channel-data command with a guessed or enumerated id and read another webview's queued response before its owner claims it. Closing a webview does not purge its queued entries, so they stay retrievable afterward. The fix scopes the queue per webview label and purges entries when a webview closes.
You are affected if you are using a version that falls within the vulnerable range and your application creates more than one webview.
tauri is vulnerable to Insecure Direct Object Reference (IDOR) in versions 2.0.0 - 2.11.5.
Upgrade the tauri library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.