Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the HTTP plugin's redirect-following logic, which checks the URL scope only against the initial URL requested by the frontend and not against subsequent redirect hops. A server on an allowed origin can issue a redirect to any other origin - including localhost services, internal hosts, and cloud metadata endpoints - and the plugin follows the full redirect chain, returning the response to the webview. This allows a network-adjacent attacker to leverage an open redirect or a controlled server to exfiltrate responses from otherwise-denied origins.
Remediation
Upgrade @tauri-apps/plugin-http to version 3.0.0-alpha.0 or higher.