GHSA-r4w5-6pfg-jxp5
Electron: ProtocolResponse.url reuses the default session cache instead of the registering session
Quick fix
GHSA-r4w5-6pfg-jxp5 — electron: upgrade to the fixed version with the command below.
npm install electron@43.0.0 Details
### Impact When a custom protocol handler returned a `ProtocolResponse` with a `url` and no `session`, Electron made the upstream request through `defaultSession` instead of the session that handled the protocol. A cached response could then be reused across otherwise isolated session partitions.
Apps that use `ProtocolResponse.url`, omit `ProtocolResponse.session`, and rely on separate sessions to isolate content are affected. Apps that set an explicit `session`, or that do not isolate content across sessions, are not affected.
### Workarounds Set `ProtocolResponse.session` explicitly so the request uses the intended session's cache.
### Fixed Versions * `43.0.0` * `42.5.1` * `41.9.1` * `40.10.6`
### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org)
Are you affected?
Enter the version of the package you're using.