Skip to main content

Electron Webview XSS Vulnerability

A vulnerability, CVE-2018-1000136, has been discovered which allows Node.js JavaScript runtime integration to be re-enabled in some Electron applications that previously disabled it.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A vulnerability, CVE-2018-1000136, has been discovered which allows Node.js JavaScript runtime integration to be re-enabled in some Electron applications that previously disabled it.

Affected platforms

The following platforms are known to be affected:

Threat details

Exploitation of this vulnerability could allow an attacker to perform cross-site scripting (XSS) attacks on affected applications.

Remediation steps

Type Step
Electron have confirmed that this vulnerability has been rectified in the their 1.7.13, 1.8.4, and 2.0.0-beta.5 releases. They have also provided mitigation code for developers who are unable to update their application's Electron version.

CVE Vulnerabilities

Last edited: 17 February 2020 12:42 pm