VDB
Sign up
HIGH7.3

GHSA-r4pf-3v7r-hh55

electron-builder's NSIS installer - execute arbitrary code on the target machine (Windows only)

Quick fix

GHSA-r4pf-3v7r-hh55 — app-builder-lib: upgrade to the fixed version with the command below.

npm install app-builder-lib@24.13.2

Details

### Impact Windows-Only: The NSIS installer makes a system call to open cmd.exe via NSExec in the `.nsh` installer script. NSExec by default searches the current directory of where the installer is located before searching `PATH`. This means that if an attacker can place a malicious executable file named cmd.exe in the same folder as the installer, the installer will run the malicious file.

### Patches Fixed in https://github.com/electron-userland/electron-builder/pull/8059

### Workarounds None, it executes at the installer-level before the app is present on the system, so there's no way to check if it exists in a current installer.

### References https://cwe.mitre.org/data/definitions/426.html https://cwe.mitre.org/data/definitions/427

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/app-builder-lib
Introduced in: 0Fixed in: 24.13.2
Fixnpm install app-builder-lib@24.13.2

References