GHSA-m55f-7gqj-fr98
Electron: Extension tab APIs operate across session boundaries
빠른 조치
GHSA-m55f-7gqj-fr98 — electron: 아래 명령으로 수정 버전으로 올리세요.
npm install electron@39.8.8 상세
### Impact Extension tab and scripting APIs were not scoped to the extension's own `session`. A malicious or compromised extension loaded into one session could navigate, script, and read from windows belonging to a different session.
Apps are only affected if they load Chrome extensions via `session.loadExtension` and rely on separate sessions to isolate that extension from other content. Apps that do not load extensions, or that use a single session, are not affected.
### Workarounds Only load extensions from sources you trust; do not rely on session separation alone to contain an extension.
### Fixed Versions * `42.0.0-beta.3` * `41.2.1` * `40.9.0` * `39.8.8`
### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org)
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.