GHSA-9qh4-3jw8-366w: High severity npm/electron vulnerability
Impact
A <webview> could enable Node.js integration in its Web Workers even when its embedder had Node.js integration disabled, giving guest content more privilege than the embedder allowed.
Apps are only affected if they enable the <webview> tag and the embedder is unsandboxed. Apps that do not use <webview>, or that keep the embedder sandboxed, are not affected.
Workarounds
Remove nodeIntegrationInWorker from the guest preferences in a will-attach-webview handler, or do not enable the <webview> tag when loading untrusted content.
Fixed Versions
44.0.0-beta.5 43.4.1 42.9.2 41.10.6
For more information
If you have any questions or comments about this advisory, email us at security@electronjs.org
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 44.0.0-beta.5 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 43.4.1 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 42.9.2 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 41.10.6 - Upgrade
Upgrade
Electronto a version that resolves this vulnerability.Fixed in 41.10.6 - Upgrade
Upgrade
Electronto a version that resolves this vulnerability.Fixed in 42.9.2 - Upgrade
Upgrade
Electronto a version that resolves this vulnerability.Fixed in 43.4.1 - Upgrade
Upgrade
Electronto a version that resolves this vulnerability.Fixed in 44.0.0-beta.5 - Configuration
Remove nodeIntegrationInWorker from the guest preferences in a will-attach-webview handler, or do not enable the <webview> tag when loading untrusted content.
Electron <webview> nodeIntegrationInWorker = removed
Event History
Frequently Asked Questions
Which Electron applications are affected?
An application is affected only if it enables the <webview> tag and uses an unsandboxed embedder. Applications that do not use <webview>, or that keep the embedder sandboxed, are not affected.
What must an attacker be able to do to exploit this issue?
The attacker must be able to get guest content loaded in a <webview> where Node.js integration in workers can be enabled through guest preferences. Exploitation also requires user interaction, as indicated by the UI:R vector.
What can be done if upgrading is not immediately possible?
In a will-attach-webview handler, remove nodeIntegrationInWorker from the guest preferences. Alternatively, do not enable the <webview> tag when loading untrusted content.
How can I determine whether my application needs remediation?
Review whether the application enables <webview>, whether its embedder is unsandboxed, and whether guest preferences can include nodeIntegrationInWorker. If <webview> is not used or the embedder remains sandboxed, the advisory states the application is not affected.
Which releases contain fixes?
Fixed releases are 44.0.0-beta.5, 43.4.1, 42.9.2, and 41.10.6.