← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 23, 2026 · 10:17via CVEFeed

CVE-2026-95626 - Tauri framework v2 CSP nonce protection bypass via data and blob URI schemes allows an XSS to RCE chains

Brief

CVE ID : CVE-2026-95626

Published : Sept. 23, 2026, 10:17 a. m.

  • 42 minutes ago

Description : Tauri's Content Security Policy hardening, which injects a random nonce to restrict script execution, provides zero protection when an application includes data: or blob: in its script-src directive. Per the CSP Level 3 specification, these scheme sources remain active even when a nonce is present, allowing arbitrary script execution without knowing the nonce.

Severity: 8.3

  • HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed