Intel

AIKIDO-2025-10140

electron is vulnerable to Undefined Behavior

Undefined Behavior Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 8, 2025

36

Low Risk

This Affects:

JSelectron
34.0.0 - 34.3.0
Fixed in 34.3.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package suffer from invalid memory access in the PDF viewer functionality, which can result in random crashes and potential instability.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Undefined Behavior in versions 34.0.0 - 34.3.0.

How to fix this

Upgrade the electron library to a patch version.