VDB
KO
HIGH 7.8

GHSA-gvcj-pfq2-wxj7

High severity vulnerability that affects electron

Details

Untrusted search path vulnerability in Atom Electron before 0.33.5 allows local users to gain privileges via a Trojan horse Node.js module in a parent directory of a directory named on a require line.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / electron
Introduced in: 0 Fixed in: 0.33.5
Fix npm install electron@0.33.5

References