GHSA-gr2m-v5gq-v685: High severity npm/electron vulnerability
Impact
Windows opened from a sandboxed top-level document did not inherit that document's HTML sandbox restrictions, so content that was meant to run sandboxed could open a window with the app's full origin. GHSA-hq2x-r82h-9wj4 covers the same issue for sandboxed iframes.
Apps are only affected if they render untrusted content in a sandboxed top-level document that allows popups. Apps that deny popups from untrusted content with setWindowOpenHandler are not affected.
Workarounds
Return { action: 'deny' } from setWindowOpenHandler for windows opened by untrusted content.
Fixed Versions
44.0.0-beta.5 43.4.1 42.9.2 41.10.6
For more information
If you have any questions or comments about this advisory, email us at security@electronjs.org
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 44.0.0-beta.5 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 43.4.1 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 42.9.2 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 41.10.6 - Configuration
Return { action: 'deny' } from setWindowOpenHandler for windows opened by untrusted content.
Electron setWindowOpenHandler = return { action: 'deny' }
Event History
Frequently Asked Questions
Which applications are exposed to this issue?
Applications are affected only if they render untrusted content in a sandboxed top-level document and allow that content to open popups. Applications that deny popups from untrusted content through setWindowOpenHandler are not affected.
What does an attacker need to exploit it?
An attacker needs their untrusted content to be rendered in a sandboxed top-level document that permits popups, and must induce a user interaction to open a window. The opened window can then have the application's full origin rather than inheriting the sandbox restrictions.
What can be done while patching is not possible?
Configure setWindowOpenHandler to return { action: 'deny' } for windows opened by untrusted content. This prevents the popup behavior required for exploitation.
Which Electron releases contain fixes?
Fixed releases are 44.0.0-beta.5, 43.4.1, 42.9.2, and 41.10.6.