electron is vulnerable to Improper Input Validation
53
Medium Risk
electron's embedded Chromium input stack accepts unvalidated mouse-capture requests from compromised renderer processes. After renderer compromise, crafted IPC can force mouse capture and leak cross-origin UI interaction data. Pre-fix builds allow cross-origin data exposure through the capture path. The backport validates SetMouseCapture requests in the browser process.
You are affected if you are using a version that falls within the vulnerable range.
electron is vulnerable to Improper Input Validation in versions 40.0.0 - 40.10.2 and 41.0.0 - 41.7.1.
Upgrade the electron library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant