electron is vulnerable to ASAR Integrity Bypass By Just Modifying The Content
78
High Risk
Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 30.0.0-alpha.1 to before 30.0.5 and 31.0.0-alpha.1 to before 31.0.0-beta.1, Electron is vulnerable to an ASAR Integrity bypass.
You are affected if you are using a version that falls within the vulnerable range and the application must be launched from a writable filesystem on Windows when the embeddedAsarIntegrityValidation and onlyLoadAppFromAsar fuses are enabled.
electron is vulnerable to ASAR Integrity Bypass By Just Modifying The Content in versions 30.0.1 - 30.0.4.
Upgrade the electron library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant