Intel

AIKIDO-2026-786409

tauri is vulnerable to Insecure Direct Object Reference (IDOR)

Insecure Direct Object Reference (IDOR)GHSA-w28w-mhc8-qvjv Published Yesterday

74

High Risk

This Affects:

RUSTtauri
2.0.0 - 2.11.5
Fixed in 2.11.6
Are you affected? Scan for Free

TL;DR

Tauri's IPC channel fetch path queues large invoke responses in a single process wide map keyed only by a sequential u32 id, shared across every webview. Any webview can call the internal fetch-channel-data command with a guessed or enumerated id and read another webview's queued response before its owner claims it. Closing a webview does not purge its queued entries, so they stay retrievable afterward. The fix scopes the queue per webview label and purges entries when a webview closes.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your application creates more than one webview.

Background info

tauri is vulnerable to Insecure Direct Object Reference (IDOR) in versions 2.0.0 - 2.11.5.

How to fix this

Upgrade the tauri library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform