Security fixes are provided for the latest release and master.
| Version | Supported |
|---|---|
| 0.11.x | ✅ |
| 0.10.x | |
| < 0.10 | ❌ |
The dashboard's Rust shell pulls glib 0.18 through Tauri → gtk-rs, and that
version carries an informational advisory (informational = "unsound", no
CVE): glib::VariantStrIter's iterator impls wrote through a shared reference,
which can lead to a NULL dereference. It is fixed in glib 0.20.
Why it is not fixed here: the fix lives in gtk-rs 0.20, and Tauri 2.x still
pins gtk 0.18 (checked with Tauri 2.12.1). It cannot be resolved from this
repository, and Throtl's own Rust code never iterates GVariant string
iterators — the affected API is only reachable from gtk-rs internals. The
Dependabot rule in .github/dependabot.yml ignores glib < 0.20 and allows the
bump as soon as Tauri moves.
Please do not open a public issue for security problems.
Use GitHub's private vulnerability reporting:
- Open the repository's Security tab.
- Click Report a vulnerability.
- Describe the issue, the affected version and steps to reproduce.
You can expect an initial response within a few days. If private reporting is not available, open a minimal issue asking for a private channel — without details.
Throtl's daemon runs as root and exposes a local Unix socket
(/run/throtl/daemon.sock). Relevant classes of issues include:
- privilege escalation from the socket API,
- unsafe rendering of the TrafficToll YAML or of the
ttcommand arguments, - path/symlink attacks around
/run/throtlor/etc/throtl.
The socket is owned by root:throtl and has mode 0660, so only members of
the throtl group (created by setup/install.sh, which also adds the invoking
user) can manage bandwidth limits. If the throtl group does not exist (a
manual start without install.sh), the daemon fails closed to 0600
(root only) and logs a hint — it never falls back to a world-writable socket.
throtl-cli doctor reports the effective permissions and throtl-cli status
exposes them as socket.restricted. No network port is ever opened.
The trust boundary is therefore "anything running as root or as a member of
group throtl" — the GUI/CLI run in the user session and reach the daemon
through that socket only. setup/install-app.sh installs the dashboard
per-user, so it inherits exactly those rights and nothing more.