electron is vulnerable to Improper Privilege Management
83
High Risk
A <webview> tag can enable Node.js integration inside its Web Workers even when the embedding app disabled Node.js integration for that guest. Guest content loaded in the <webview> gains more privilege than the embedder configured, exposing Node.js APIs to workers spawned from untrusted content. This affects apps that enable the <webview> tag with an unsandboxed embedder. The fix propagates the embedder's Node.js integration restriction to Web Workers spawned inside the guest.
You are affected if you are using a version that falls within the vulnerable range and you enable the <webview> tag with an unsandboxed embedder.
electron is vulnerable to Improper Privilege Management in versions 1.0.0 - 41.10.5, 42.0.0 - 42.9.1 and 43.0.0 - 43.4.0.
Upgrade the electron library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.