tauri-plugin-shell
All of the official Tauri plugins in one place!
Activity
- Latest release
- 19h ago
- Total releases
- 37
- Cadence
- ~17 days
- Last 12 months
- 6
Reach
- Downloads
- 10.8M
- Stars
- 1.8k
Details
- License
- Apache-2.0 OR MIT
- First release
- May 24, 2023
| Version | Released | |
|---|---|---|
3.0.0-alpha.0
pre
|
3.0.0-alpha.0
pre
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
2.3.6
patch
|
2.3.6
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
2.3.5
unknown
| ||
2.3.4
unknown
| ||
2.3.3
unknown
| ||
2.3.2
unknown
| ||
2.3.1
unknown
| ||
2.3.0
unknown
| ||
2.2.2
unknown
| ||
2.2.1
unknown
| ||
2.2.0
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.2
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.1
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0-rc.4
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0-rc.3
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0-rc.2
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0-rc.1
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0-rc.0
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0-beta.10
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev |
2.0.0-beta.10
unknown
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
2.0.0-beta.9
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0-beta.8
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0-beta.7
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0-beta.6
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0-beta.5
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0-beta.4
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0-beta.3
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0-beta.2
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0-beta.1
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0-beta.0
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0-alpha.6
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev |
2.0.0-alpha.6
unknown
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.0.0-alpha.5
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev |
2.0.0-alpha.5
unknown
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.0.0-alpha.4
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev |
2.0.0-alpha.4
unknown
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.0.0-alpha.3
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev |
2.0.0-alpha.3
unknown
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.0.0-alpha.2
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev |
2.0.0-alpha.2
unknown
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.0.0-alpha.1
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev |
2.0.0-alpha.1
unknown
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.0.0-alpha.0
unknown
1 CVE
CVE-2025-31477
GHSA-c9pr-q8gx-3mgp
Apr 02, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
Network
Low
None
None
ImpactThe Tauri This default restriction was not functional due to improper validation of the allowed protocols, allowing for potentially dangerous protocols like By passing untrusted user input to the You are not affected if you have explicitly configured a validation regex or manually set the Technically the scope was never a limitation for the rust side as it is not seen as an enforceable security boundary but we decided to mark the rust crate as affected since the plugin does not need to be a frontend dependency to be exposed. PatchesThe issue has been patched in the WorkaroundsA way to prevent arbitrary protocols would be setting the shell plugin configuration value
The above will only allow If the
Alternatively we recommend usage of the ReferencesPoCThis is a windows specific proof of concept.
Fixed in
2.2.1
References Updated Sep 10, 2026 · Source: OSV.dev |