GHSA-v3j7-r9gq-3gjw
Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
Quick fix
GHSA-v3j7-r9gq-3gjw — electron: upgrade to the fixed version with the command below.
npm install electron@42.0.0 Details
### Impact A custom scheme registered with `supportFetchAPI: true` but without `corsEnabled: true` was not subject to CORS enforcement. A page loaded from a remote origin could therefore `fetch()` or `XMLHttpRequest` that scheme cross-origin and read the full response body, rather than the read being blocked.
Apps that serve sensitive data from such a scheme and load remote or untrusted content in a renderer are affected. Apps that set `corsEnabled: true`, or that do not load untrusted content, are not affected.
### Workarounds Set `corsEnabled: true` on schemes that must enforce CORS, and validate the request `Origin` in your protocol handler before returning sensitive data.
### Fixed Versions * `42.0.0` * `41.4.0` * `40.9.3` * `39.8.10`
### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org)
Are you affected?
Enter the version of the package you're using.