VDB
KO
MEDIUM 5.9

GHSA-r4w5-6pfg-jxp5

Electron: ProtocolResponse.url reuses the default session cache instead of the registering session

Quick fix

GHSA-r4w5-6pfg-jxp5 — electron: upgrade to the fixed version with the command below.

npm install electron@43.0.0

Details

### Impact When a custom protocol handler returned a `ProtocolResponse` with a `url` and no `session`, Electron made the upstream request through `defaultSession` instead of the session that handled the protocol. A cached response could then be reused across otherwise isolated session partitions.

Apps that use `ProtocolResponse.url`, omit `ProtocolResponse.session`, and rely on separate sessions to isolate content are affected. Apps that set an explicit `session`, or that do not isolate content across sessions, are not affected.

### Workarounds Set `ProtocolResponse.session` explicitly so the request uses the intended session's cache.

### Fixed Versions * `43.0.0` * `42.5.1` * `41.9.1` * `40.10.6`

### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / electron
Introduced in: 43.0.0-alpha.1 Fixed in: 43.0.0
Fix npm install electron@43.0.0
npm / electron
Introduced in: 42.0.0-alpha.1 Fixed in: 42.5.1
Fix npm install electron@42.5.1
npm / electron
Introduced in: 41.0.0-alpha.1 Fixed in: 41.9.1
Fix npm install electron@41.9.1
npm / electron
Introduced in: 40.0.0-alpha.1 Fixed in: 40.10.6
Fix npm install electron@40.10.6

References