CVE-2018-1000136: Input Validation
A vulnerability has been discovered which allows Node.js integration to be re-enabled in some Electron applications that disable it.
For the application to be impacted by this vulnerability it must meet all of these conditions
- Runs on Electron 1.7, 1.8, or a 2.0.0-beta - Allows execution of arbitrary remote code - Disables Node.js integration - Does not explicitly declare webviewTag: false in its webPreferences - Does not enable the nativeWindowOption option - Does not intercept new-window events and manually override event.newGuest without using the supplied options tag
Recommendation
Update to electron version 1.7.13, 1.8.4, or 2.0.0-beta.5 or later.
If you are unable to update your Electron version can mitigate the vulnerability with the following code.
js app.on('web-contents-created', (event, win) => { win.on('new-window', (event, newURL, frameName, disposition, options, additionalFeatures) => { if (!options.webPreferences) options.webPreferences = {}; options.webPreferences.nodeIntegration = false; options.webPreferences.nodeIntegrationInWorker = false; options.webPreferences.webviewTag = false; delete options.webPreferences.preload; }) })
// and IF you don't use WebViews at all, // you might also want app.on('web-contents-created', (event, win) => { win.on('will-attach-webview', (event, webPreferences, params) => { event.preventDefault(); }) })
Other sources
Electron version 1.7 up to 1.7.12; 1.8 up to 1.8.3 and 2.0.0 up to 2.0.0-beta.3 contains an improper handling of values vulnerability in Webviews that can result in remote code execution. This attack appear to be exploitable via an app which allows execution of 3rd party code AND disallows node integration AND has not specified if webview is enabled/disabled. This vulnerability appears to have been fixed in 1.7.13, 1.8.4, 2.0.0-beta.4.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-1000136?
CVE-2018-1000136 is a vulnerability in Electron versions 1.7 up to 1.7.12, 1.8 up to 1.8.3, and 2.0.0 up to 2.0.0-beta.3 that allows Node.js integration to be re-enabled in some Electron applications that disable it.
Which Electron versions are affected by CVE-2018-1000136?
Electron versions 1.7 up to 1.7.12, 1.8 up to 1.8.3, and 2.0.0 up to 2.0.0-beta.3 are affected by CVE-2018-1000136.
What is the severity of CVE-2018-1000136?
CVE-2018-1000136 has a severity rating of 8.1 (High).
How can I fix CVE-2018-1000136?
To fix CVE-2018-1000136, you should update Electron to versions 1.7.13, 1.8.4, or 2.0.0-beta.5, depending on the version you are using.
Where can I find more information about CVE-2018-1000136?
You can find more information about CVE-2018-1000136 on the NVD website (https://nvd.nist.gov/vuln/detail/CVE-2018-1000136), the Electron blog (https://electronjs.org/blog/webview-fix), and the npm advisory page (https://www.npmjs.com/advisories/574).