OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-95626

HIGH · CVSS 8.3 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Tauri's Content Security Policy hardening is vulnerable when applications include data: or blob: in their script-src directive, as these sources bypass nonce restrictions, enabling arbitrary script execution. This flaw poses a significant risk to applications that rely on CSP for security, as it undermines the intended protection against cross-site scripting (XSS) attacks. Developers and security teams using Tauri should prioritize addressing this vulnerability to safeguard their applications from potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-95626
Severity
HIGH
CVSS
8.3
EPSS
0.28%

Original NVD Description

Tauri's Content Security Policy hardening, which injects a random nonce to restrict script execution, provides zero protection when an application includes data: or blob: in its script-src directive. Per the CSP Level 3 specification, these scheme sources remain active even when a nonce is present, allowing arbitrary script execution without knowing the nonce.