Intel

AIKIDO-2024-10255

@electron/asar is vulnerable to UNIX Symbolic Link (Symlink) Following

UNIX Symbolic Link (Symlink) Following Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Sep 11, 2024

69

Medium Risk

This Affects:

js@electron/asar
0.2.0 - 3.2.10
Fixed in 3.2.11
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to symlink following. When extracting a file or directory, the package fails to properly handle symbolic links that resolve to targets outside of the intended control sphere. This allows an attacker to potentially manipulate the product to operate on unauthorized files.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@electron/asar is vulnerable to UNIX Symbolic Link (Symlink) Following in versions 0.2.0 - 3.2.10.

How to fix this

Upgrade the @electron/asar library to the patch version.