HIGHnpm →
Electron: DevTools embedder handler executes arbitrary files via shell open
Electron: DevTools embedder handler executes arbitrary files via shell open
Affected packages
- electron
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/electron/electron/security/advisories/GHSA-f2r8-jv7c-xqmp
- https://github.com/electron/electron/pull/50937
- https://github.com/electron/electron/pull/50938
- https://github.com/electron/electron/pull/51114
- https://github.com/electron/electron/pull/51115
- https://github.com/electron/electron/commit/10fb5b39c5287f70c4bbcab4c24197f3871ec322
- https://github.com/electron/electron/commit/27bf1cae9274d5025684c7268496f435b7e06b44
- https://github.com/electron/electron/commit/7a1eb7e5585991b3726cedb890a6244f327f43de
- https://github.com/electron/electron
- https://github.com/electron/electron/releases/tag/v39.8.9
- https://github.com/electron/electron/releases/tag/v40.9.2
- https://github.com/electron/electron/releases/tag/v41.2.1
- https://github.com/electron/electron/releases/tag/v42.0.0-beta.3
Structured record: https://osv.dev/vulnerability/GHSA-f2r8-jv7c-xqmp
Recommended response stack
Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta