VDB
Sign up
MEDIUM4.3

GHSA-6h98-cf9g-vmg2

Electron vulnerable to URL spoofing via PDFium

Quick fix

GHSA-6h98-cf9g-vmg2 — electron: upgrade to the fixed version with the command below.

npm install electron@1.7.6

Details

Electron version 1.7.0 - 1.7.5 is vulnerable to a URL Spoofing problem when opening PDFs in PDFium resulting loading arbitrary PDFs that a hacker can control.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/electron
Introduced in: 1.7.0Fixed in: 1.7.6
Fixnpm install electron@1.7.6

References