VDB
Sign up
CRITICAL9.8

GHSA-4w88-rjj3-x7wp

Chromium Remote Code Execution in electron

Quick fix

GHSA-4w88-rjj3-x7wp — electron: upgrade to the fixed version with the command below.

npm install electron@1.6.14

Details

Affected versions of `ElectronJS` are susceptible to a remote code execution vulnerability that occurs when an affected application access remote content, even if the [sandbox option](https://electron.atom.io/docs/api/sandbox-option) is enabled.

## Recommendation

Update to electron version 1.7.8 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/electron
Introduced in: 0Fixed in: 1.6.14
Fixnpm install electron@1.6.14
npm/electron
Introduced in: 1.7.0Fixed in: 1.7.8
Fixnpm install electron@1.7.8

References