CVE-2026-95625

Summary

The Tauri updater plugin verifies update binaries using minisign signatures, but the signature covers only the raw binary bytes. The update manifest – which contains the version number, download URL, and signature – is fetched over TLS but is never itself signed or authenticated. Because the only anti-rollback check compares the manifest's version field against the current version, and that field is unsigned, an attacker who can serve a crafted manifest can force installation of any older signed release without possessing the developer's private key.

Affected Software

VendorProductVersion RangeStatus
Tauritauri-plugin-updater2.0.0 < 2.12.0affected
Tauritauri-plugin-updater2.12.0 <= *affected

Weaknesses

  • CWE-354: CWE-354: Improper Validation of Integrity Check Value

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References