VDB
Sign up
MEDIUM5.8

GHSA-28m8-9j7v-x499

Tauri's readDir Endpoint Scope can be Bypassed With Symbolic Links

Details

### Impact Due to missing canonicalization when `readDir` is called recursively, it was possible to display directory listings outside of the defined `fs` scope. This required a crafted symbolic link or junction folder inside an allowed path of the `fs` scope. No arbitrary file content could be leaked.

### Patches The issue has been resolved in https://github.com/tauri-apps/tauri/pull/5123 and the implementation now properly checks if the requested (sub) directory is a symbolic link outside of the defined `scope`.

### Workarounds Disable the `readDir` endpoint in the `allowlist` inside the `tauri.conf.json`.

### For more information

This issue was initially reported by [martin-ocasek]( https://github.com/martin-ocasek) in [#4882](https://github.com/tauri-apps/tauri/issues/4882).

If you have any questions or comments about this advisory: * Open an issue in [tauri](https://github.com/tauri-apps/tauri) * Email us at [security@tauri.app](mailto:security@tauri.app)

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/tauri
Introduced in: 0Fixed in: 1.0.6

Upgrade tauri to 1.0.6 or newer (ecosystem crates.io).

References