VDB
KO
MEDIUM 6.0

GHSA-5c9j-mhmv-5xgx

Electron: shell.openPath path validation bypass via embedded null byte

Quick fix

GHSA-5c9j-mhmv-5xgx — electron: upgrade to the fixed version with the command below.

npm install electron@42.0.0-beta.1

Details

### Impact `shell.openPath()` did not reject paths containing embedded null bytes. Apps that perform string-only validation of file paths (for example, checking the file extension) before passing them to `shell.openPath()` could be bypassed, allowing an attacker-controlled path to open a different file than the one that passed validation.

Apps are only affected if they pass paths derived from untrusted input to `shell.openPath()` and rely on string-based validation without a filesystem check. Node's `fs` APIs already reject paths containing null bytes, so apps that call `fs.existsSync()`, `fs.stat()`, or similar before `shell.openPath()` are not affected. Apps that do not call `shell.openPath()` with untrusted input are not affected.

### Workarounds Reject any path containing a null byte before passing it to `shell.openPath()`: ```js if (filePath.includes('\0')) throw new Error('invalid path'); ```

### Fixed Versions * `42.0.0-beta.1` * `41.1.1` * `40.9.0` * `39.8.6`

### For more information If you have any questions or comments about this advisory, email us at [security@electronjs.org](mailto:security@electronjs.org)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / electron
Introduced in: 42.0.0-alpha.1 Fixed in: 42.0.0-beta.1
Fix npm install electron@42.0.0-beta.1
npm / electron
Introduced in: 41.0.0-alpha.1 Fixed in: 41.1.1
Fix npm install electron@41.1.1
npm / electron
Introduced in: 40.0.0-alpha.1 Fixed in: 40.9.0
Fix npm install electron@40.9.0
npm / electron
Introduced in: 0 Fixed in: 39.8.6
Fix npm install electron@39.8.6

References