VDB
Sign up
MEDIUM6.8

GHSA-f9mq-jph6-9mhm

Arbitrary file read via window-open IPC in Electron

Quick fix

GHSA-f9mq-jph6-9mhm — electron: upgrade to the fixed version with the command below.

npm install electron@7.2.4

Details

### Impact The vulnerability allows arbitrary local file read by defining unsafe window options on a child window opened via window.open.

### Workarounds Ensure you are calling `event.preventDefault()` on all [`new-window`](https://electronjs.org/docs/api/web-contents#event-new-window) events where the `url` or `options` is not something you expect.

### Fixed Versions * `9.0.0-beta.21` * `8.2.4` * `7.2.4`

### For more information If you have any questions or comments about this advisory: * Email us at [security@electronjs.org](mailto:security@electronjs.org)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/electron
Introduced in: 0Fixed in: 7.2.4
Fixnpm install electron@7.2.4
npm/electron
Introduced in: 8.0.0Fixed in: 8.2.4
Fixnpm install electron@8.2.4

References