GHSA-9qh4-3jw8-366wHighCVSS 8.3
Electron: <webview> can enable Node.js integration in Web Workers despite embedder restrictions
🔗 CVE IDs covered (1)
📋 Description
Impact
A <webview> could enable Node.js integration in its Web Workers even when its embedder had Node.js integration disabled, giving guest content more privilege than the embedder allowed.
Apps are only affected if they enable the <webview> tag and the embedder is unsandboxed. Apps that do not use <webview>, or that keep the embedder sandboxed, are not affected.
Workarounds
Remove nodeIntegrationInWorker from the guest preferences in a will-attach-webview handler, or do not enable the <webview> tag when loading untrusted content.
Fixed Versions
44.0.0-beta.543.4.142.9.241.10.6
For more information
If you have any questions or comments about this advisory, email us at [email protected]
🎯 Affected products4
- npm/electron:< 41.10.6
- npm/electron:>= 42.0.0-alpha.1, < 42.9.2
- npm/electron:>= 43.0.0-alpha.1, < 43.4.1
- npm/electron:>= 44.0.0-alpha.1, < 44.0.0-beta.5
🔗 References (10)
- https://github.com/electron/electron/security/advisories/GHSA-9qh4-3jw8-366w
- https://github.com/electron/electron/commit/6462a2e1dc4e6adffd3b7d9b9be1474c45dcbbe2
- https://github.com/electron/electron/commit/9a675aef8822bae4088567822969f900b3a37671
- https://github.com/electron/electron/commit/b3ae0aab5cf81c2ed03d04df1ae8e69ecfab7886
- https://github.com/electron/electron/commit/cd34f335c8664613db5b6e61ae51e2e1846233ae
- https://github.com/electron/electron/releases/tag/v41.10.6
- https://github.com/electron/electron/releases/tag/v42.9.2
- https://github.com/electron/electron/releases/tag/v43.4.1
- https://github.com/electron/electron/releases/tag/v44.0.0-beta.5
- https://github.com/advisories/GHSA-9qh4-3jw8-366w