electron is vulnerable to Command Injection
80
High Risk
A type confusion vulnerability in WebAssembly in Google Chrome versions prior to 123.0.6312.86 allowed remote attackers to execute arbitrary code through a specially crafted HTML page. (Chromium security severity: High)
You are affected if you are using a version that falls within the vulnerable range.
electron is vulnerable to Command Injection in versions 29.0.0 - 29.1.6, 28.0.0 - 28.2.9 and 27.0.0 - 27.3.8.
Upgrade the electron library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant