{"api_version":"v1","generated_at":"2026-10-08T11:00:00+00:00","product":{"cve_count":2,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-tauri-tauri-plugin-updater-2a995a5926da","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"tauri-plugin-updater","next_cursor":null,"observations":[{"affected":"tauri-plugin-updater: 2.0.0 < 2.12.0, 2.12.0 \u2264 *","affected_versions_present":true,"cve_id":"CVE-2026-95625","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-95625","fixed":"addressed in tauri-plugin-updater 2.12.0, and it has to be switched on. The new requireSignedVersion option compares the version announced by the endpoint against the version recorded in the signature's trusted comment, which the signature does cover, and rejects the update when they differ.","last_modified":"2026-09-23T14:10:35.332Z","patch_url":"https://github.com/tauri-apps/plugins-workspace/security/advisories/GHSA-j38x-g3m3-95fr","primary_source":"","published":"2026-09-23T08:51:53.922Z"},{"affected":"tauri-plugin-updater: 2.8.0 < 2.12.0","affected_versions_present":true,"cve_id":"CVE-2026-95624","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-95624","fixed":"Fixed in tauri-plugin-updater 2.12.0. allowDowngrades was removed from the check command and is now read from the plugin configuration instead, where the frontend cannot reach it, and it defaults to false. An application that provides its own version comparator still takes precedence.","last_modified":"2026-09-22T19:30:22.534Z","patch_url":"https://github.com/tauri-apps/tauri/security/advisories/GHSA-rjc6-5hfg-grp9","primary_source":"","published":"2026-09-22T17:16:25.195Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"Tauri"}}
