tauri
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalyreferences/ipc-commands.md
LOWAnomalyLOW
references/ipc-commands.md
No malicious behavior or supply-chain attack indicators are present. The fragment is legitimate IPC documentation. However, if the shown commands are used with untrusted frontend content, `fetch_data` may enable SSRF and `read_file` may enable arbitrary local file disclosure because neither input is restricted. These are application-level security risks requiring validation, allowlists, and appropriate Tauri capability controls.
Confidence: 98%Severity: 58%
Audit Metadata