GHSA-9f4c-93c8-jc8g
Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path
Quick fix
GHSA-9f4c-93c8-jc8g — electron: upgrade to the fixed version with the command below.
npm install electron@42.0.1 Details
### Impact A sandboxed iframe without the `allow-popups` keyword could still open a new window (or trigger `setWindowOpenHandler`) with no user interaction, because new-window navigations taking the OpenURL path did not apply the iframe sandbox popup restriction.
Apps that embed untrusted content in sandboxed iframes and rely on the absence of `allow-popups` to prevent window creation are affected. Apps that deny window creation in `setWindowOpenHandler`, or that do not embed untrusted content in sandboxed iframes, are not affected.
### Workarounds Return `{ action: 'deny' }` from `setWindowOpenHandler` for any content you do not trust, rather than relying on the iframe sandbox alone.
### Fixed Versions * `42.0.1` * `41.10.3` * `39.8.10`
### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org)
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/electron/electron/security/advisories/GHSA-9f4c-93c8-jc8g [WEB]
- https://github.com/electron/electron/pull/51437 [WEB]
- https://github.com/electron/electron/pull/51438 [WEB]
- https://github.com/electron/electron/pull/51439 [WEB]
- https://github.com/electron/electron/commit/3ff23c52ab364a0afc6ab5bd7851291d3159de57 [WEB]
- https://github.com/electron/electron/commit/57cbe329c4ae8aab5ac5ebdcb588adc9a11de0d3 [WEB]
- https://github.com/electron/electron/commit/68cf8b7d9122260f6b534a69a82c701a56cf159f [WEB]
- https://github.com/electron/electron [PACKAGE]
- https://github.com/electron/electron/releases/tag/v39.8.10 [WEB]
- https://github.com/electron/electron/releases/tag/v41.10.3 [WEB]
- https://github.com/electron/electron/releases/tag/v42.0.1 [WEB]