GHSA-m55f-7gqj-fr98
Electron: Extension tab APIs operate across session boundaries
Quick fix
GHSA-m55f-7gqj-fr98 — electron: upgrade to the fixed version with the command below.
npm install electron@39.8.8 Details
### Impact Extension tab and scripting APIs were not scoped to the extension's own `session`. A malicious or compromised extension loaded into one session could navigate, script, and read from windows belonging to a different session.
Apps are only affected if they load Chrome extensions via `session.loadExtension` and rely on separate sessions to isolate that extension from other content. Apps that do not load extensions, or that use a single session, are not affected.
### Workarounds Only load extensions from sources you trust; do not rely on session separation alone to contain an extension.
### Fixed Versions * `42.0.0-beta.3` * `41.2.1` * `40.9.0` * `39.8.8`
### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org)
Are you affected?
Enter the version of the package you're using.
Affected packages
42.0.0-alpha.1 Fixed in: 42.0.0-beta.3 npm install electron@42.0.0-beta.3