electron is vulnerable to Sandbox Bypass
42
Medium Risk
Electron opens new windows for links triggered inside a sandboxed iframe through the OpenURL navigation path. On that path the opened window did not inherit the iframe's sandbox restrictions, so content confined to a sandboxed iframe could obtain a window that runs without those restrictions. This lets untrusted embedded content escape the sandbox boundary the application relied on. The fix makes such windows inherit the iframe's sandbox flags unless allow-popups-to-escape-sandbox is set.
You are affected if you are running a version that falls within a vulnerable range and your application embeds untrusted content in sandboxed iframes and relies on the iframe sandbox to restrict windows opened from that content.
electron is vulnerable to Sandbox Bypass in versions 1.3.1 - 41.10.3 and 42.0.0 - 42.5.1.
Upgrade the electron library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant