Vulnerabilities & PatchesEmerging1 src
CVE-2026-95626 - Tauri framework v2 CSP nonce protection bypass via data and blob URI schemes allows an XSS to RCE chains
CVE ID : CVE-2026-95626
Published : Sept. 23, 2026, 10:17 a. m.
• 42 minutes ago
Description : Tauri's Content Security Policy hardening, which injects a random nonce to restrict script execution, provides zero protection when an application includes data: or blob: in its script-src directive. Per the CSP Level 3 specification, these scheme sources remain active even when a nonce is present, allowing arbitrary script execution without knowing the nonce.
Severity: 8.3
• HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...