VDB
KO
MEDIUM 4.3

GHSA-6h98-cf9g-vmg2

Electron vulnerable to URL spoofing via PDFium

Details

Electron version 1.7.0 - 1.7.5 is vulnerable to a URL Spoofing problem when opening PDFs in PDFium resulting loading arbitrary PDFs that a hacker can control.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / electron
Introduced in: 1.7.0 Fixed in: 1.7.6
Fix npm install electron@1.7.6

References