CyberRota Analysis
AI-GeneratedTauri's Content Security Policy hardening is vulnerable when applications include data: or blob: in their script-src directive, as these sources bypass nonce restrictions, enabling arbitrary script execution. This flaw poses a significant risk to applications that rely on CSP for security, as it undermines the intended protection against cross-site scripting (XSS) attacks. Developers and security teams using Tauri should prioritize addressing this vulnerability to safeguard their applications from potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Tauri's Content Security Policy hardening, which injects a random nonce to restrict script execution, provides zero protection when an application includes data: or blob: in its script-src directive. Per the CSP Level 3 specification, these scheme sources remain active even when a nonce is present, allowing arbitrary script execution without knowing the nonce.