electron is vulnerable to Insufficient Policy Enforcement
43
Medium Risk
electron's embedded Chromium service worker static router can accept invalid or opaque cache responses as cache sources. Crafted HTML that registers service workers with static routing can bypass intended same-origin isolation for cached fetches. Pre-fix versions allow cross-origin policy bypass through the cache source path. The backport blocks invalid responses and enables default CORP and opaque checks for static router cache sources.
You are affected if you are using a version that falls within the vulnerable range and applications use service worker static routing.
electron is vulnerable to Insufficient Policy Enforcement in versions 40.0.0 - 40.10.2, 41.0.0 - 41.7.1 and 42.0.0 - 42.3.3.
Upgrade the electron library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant