electron is vulnerable to Heap-based Buffer Overflow
40
Medium Risk
Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 28.3.2, 29.3.3, and 30.0.3, the nativeImage.createFromPath() and nativeImage.createFromBuffer() functions call a function downstream that is vulnerable to a heap buffer overflow. An Electron program that uses either of the affected functions is vulnerable to a buffer overflow if an attacker is in control of the image's height, width, and contents.
You are affected if you are using a version that falls within the vulnerable range.
electron is vulnerable to Heap-based Buffer Overflow in versions 28.0.0 - 28.3.1, 29.0.0 - 29.3.2 and 30.0.0 - 30.0.2.
Upgrade the electron library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant