GHSA-5c9j-mhmv-5xgx
Electron: shell.openPath path validation bypass via embedded null byte
Quick fix
GHSA-5c9j-mhmv-5xgx — electron: upgrade to the fixed version with the command below.
npm install electron@42.0.0-beta.1 Details
### Impact `shell.openPath()` did not reject paths containing embedded null bytes. Apps that perform string-only validation of file paths (for example, checking the file extension) before passing them to `shell.openPath()` could be bypassed, allowing an attacker-controlled path to open a different file than the one that passed validation.
Apps are only affected if they pass paths derived from untrusted input to `shell.openPath()` and rely on string-based validation without a filesystem check. Node's `fs` APIs already reject paths containing null bytes, so apps that call `fs.existsSync()`, `fs.stat()`, or similar before `shell.openPath()` are not affected. Apps that do not call `shell.openPath()` with untrusted input are not affected.
### Workarounds Reject any path containing a null byte before passing it to `shell.openPath()`: ```js if (filePath.includes('\0')) throw new Error('invalid path'); ```
### Fixed Versions * `42.0.0-beta.1` * `41.1.1` * `40.9.0` * `39.8.6`
### For more information If you have any questions or comments about this advisory, email us at [security@electronjs.org](mailto:security@electronjs.org)
Are you affected?
Enter the version of the package you're using.
Affected packages
42.0.0-alpha.1 Fixed in: 42.0.0-beta.1 npm install electron@42.0.0-beta.1