Improper Authorization Affecting @tauri-apps/plugin-updater package, versions <2.12.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.45% (39th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improper Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-TAURIAPPSPLUGINUPDATER-20078986
  • published24 Sept 2026
  • disclosed22 Sept 2026
  • creditYuval Moravchick

Introduced: 22 Sep 2026

NewCVE-2026-95624  (opens in a new tab)
CWE-285  (opens in a new tab)

How to fix?

Upgrade @tauri-apps/plugin-updater to version 2.12.0 or higher.

Overview

@tauri-apps/plugin-updater is a plugin-updater

Affected versions of this package are vulnerable to Improper Authorization via the allowDowngrades option exposed to the frontend JavaScript API, which allowed any web content running inside a Tauri application to request installation of an older, previously released version of the application. Because the updater only verifies the cryptographic signature of the downloaded artifact and not whether the version is newer than the currently running one, a malicious or compromised web page could trigger a downgrade to a version known to contain vulnerabilities. The fix removes the allowDowngrades option from the frontend API and moves control of this behaviour exclusively to the application-level configuration, where it cannot be influenced by untrusted web content.

CVSS Base Scores

version 4.0
version 3.1