MEDIUM4.3
GHSA-6h98-cf9g-vmg2
Electron vulnerable to URL spoofing via PDFium
Quick fix
GHSA-6h98-cf9g-vmg2 — electron: upgrade to the fixed version with the command below.
npm install electron@1.7.6Details
Electron version 1.7.0 - 1.7.5 is vulnerable to a URL Spoofing problem when opening PDFs in PDFium resulting loading arbitrary PDFs that a hacker can control.
Are you affected?
Enter the version of the package you're using.