@electron/asar is vulnerable to UNIX Symbolic Link (Symlink) Following
69
Medium Risk
Affected versions of the package are vulnerable to symlink following. When extracting a file or directory, the package fails to properly handle symbolic links that resolve to targets outside of the intended control sphere. This allows an attacker to potentially manipulate the product to operate on unauthorized files.
You are affected if you are using a version that falls within the vulnerable range.
@electron/asar is vulnerable to UNIX Symbolic Link (Symlink) Following in versions 0.2.0 - 3.2.10.
Upgrade the @electron/asar library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant