Electron Webview XSS Vulnerability
A vulnerability, CVE-2018-1000136, has been discovered which allows Node.js JavaScript runtime integration to be re-enabled in some Electron applications that previously disabled it.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
A vulnerability, CVE-2018-1000136, has been discovered which allows Node.js JavaScript runtime integration to be re-enabled in some Electron applications that previously disabled it.
Affected platforms
The following platforms are known to be affected:
Threat details
Exploitation of this vulnerability could allow an attacker to perform cross-site scripting (XSS) attacks on affected applications.
Remediation steps
| Type | Step |
|---|---|
|
Electron have confirmed that this vulnerability has been rectified in the their 1.7.13, 1.8.4, and 2.0.0-beta.5 releases. They have also provided mitigation code for developers who are unable to update their application's Electron version. |
CVE Vulnerabilities
Last edited: 17 February 2020 12:42 pm