electron is vulnerable to Improper Input Validation
53
Medium Risk
electron's embedded Chromium input stack accepts unvalidated mouse-capture requests from compromised renderer processes. After renderer compromise, crafted IPC can force mouse capture and leak cross-origin UI interaction data. Pre-fix builds allow cross-origin data exposure through the capture path. The backport validates SetMouseCapture requests in the browser process.
You are affected if you are using a version that falls within the vulnerable range.
electron is vulnerable to Improper Input Validation in versions 40.0.0 - 40.10.2 and 41.0.0 - 41.7.1.
Upgrade the electron library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant