VDB
KO
MEDIUM 5.3

GHSA-v93f-fgjr-hjrj

Electron: window.open features string controls some window options considered privileged

Quick fix

GHSA-v93f-fgjr-hjrj — electron: upgrade to the fixed version with the command below.

npm install electron@39.8.8

Details

### Impact Some window options supplied by web content in the `window.open()` features string were applied to the new `BrowserWindow` without an allowlist. Untrusted content could set window options it should not control, including options that cause the main process to access attacker-chosen file or network paths.

Apps are only affected if untrusted content can call `window.open()` and the app does not override child window options via `setWindowOpenHandler`. Apps that deny `window.open()` for untrusted content, or set `overrideBrowserWindowOptions` explicitly, are not affected.

### Workarounds Return `{ action: 'deny' }` from `setWindowOpenHandler` for untrusted content, or supply `overrideBrowserWindowOptions` so every window option is set explicitly.

### Fixed Versions * `42.0.0-beta.3` * `41.2.1` * `40.9.0` * `39.8.8`

### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / electron
Introduced in: 0 Fixed in: 39.8.8
Fix npm install electron@39.8.8
npm / electron
Introduced in: 40.0.0-alpha.1 Fixed in: 40.9.0
Fix npm install electron@40.9.0
npm / electron
Introduced in: 41.0.0-alpha.1 Fixed in: 41.2.1
Fix npm install electron@41.2.1
npm / electron
Introduced in: 42.0.0-alpha.1 Fixed in: 42.0.0-beta.3
Fix npm install electron@42.0.0-beta.3

References