{"id":"CVE-2023-34460","aliases":["GHSA-wmff-grcw-jcfm"],"url":"https://o3.security/vulnerability/CVE-2023-34460","summary":"Tauri vulnerable to Regression on Filesystem Scope Checks for Dotfiles","details":"### Impact\nThe 1.4.0 release includes a regression on the filesystem scope check for dotfiles on Linux and macOS.\n\nPreviously dotfiles (eg. `$HOME/.ssh/`) were not implicitly allowed by the glob wildcard scopes (eg. `$HOME/*`), but a regression was introduced when a configuration option for this behavior was implemented and dotfiles were implicitly allowed.\n\nOnly Tauri applications using wildcard scopes in the `fs` endpoint are affected.\nOnly macOS and Linux systems are affected.\n\n### Patches\nThe regression has been patched on `v1.4.1`.\n\n### Workarounds\nThere are no known workarounds at this time, users should update to `v1.4.1` immediately.\n\n### References\nSee the [original advisory](https://github.com/tauri-apps/tauri/security/advisories/GHSA-6mv3-wm7j-h4w5) for more information.\n\n### For more Information\nIf you have any questions or comments about this advisory:\n\nOpen an issue in tauri\nEmail us at [security@tauri.app](mailto:security@tauri.app)","published":"2023-06-23T19:09:54.173Z","modified":"2026-09-16T03:30:15.027956666Z","cvss":{"score":4.8,"severity":"MEDIUM","vector":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"tauri","fixedVersion":"1.4.1"}],"fix":{"url":"https://github.com/tauri-apps/tauri/commit/066c09a6ea06f42f550d090715e06beb65cd5564","label":"tauri-apps/tauri@066c09a"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/34xxx/CVE-2023-34460.json"},{"type":"ADVISORY","url":"https://github.com/tauri-apps/tauri/security/advisories/GHSA-wmff-grcw-jcfm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-34460"},{"type":"FIX","url":"https://github.com/tauri-apps/tauri/commit/066c09a6ea06f42f550d090715e06beb65cd5564"},{"type":"FIX","url":"https://github.com/tauri-apps/tauri/pull/6969#discussion_r1232018347"},{"type":"FIX","url":"https://github.com/tauri-apps/tauri/pull/7227"},{"type":"WEB","url":"https://github.com/tauri-apps/tauri/security/advisories/GHSA-6mv3-wm7j-h4w5"},{"type":"PACKAGE","url":"https://github.com/tauri-apps/tauri"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-16T03:30:15.027956666Z"}}