GHSA-hq2x-r82h-9wj4: High severity npm/electron vulnerability
Impact
Popups opened from a sandboxed iframe through a link (for example target="blank" or a middle-click) did not inherit the iframe's HTML sandbox restrictions. Content that was meant to run sandboxed could open a popup with the embedding app's full origin, gaining access to that origin's cookies, storage, and same-origin scripting.
Apps are only affected if they embed untrusted content in iframes sandboxed with allow-scripts allow-popups. Apps that do not embed untrusted content in sandboxed iframes are not affected.
Workarounds
Use setWindowOpenHandler on the parent WebContents to deny or constrain popups opened from sandboxed frames, or do not apply allow-popups to sandboxed iframes that render untrusted content.
Fixed Versions
43.0.0 42.5.2 41.10.4
For more information
If you have any questions or comments about this advisory, email us at security@electronjs.org
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 43.0.0 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 42.5.2 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 41.10.4 - Upgrade
Upgrade
Electronto a version that resolves this vulnerability.Fixed in 41.10.4 - Upgrade
Upgrade
Electronto a version that resolves this vulnerability.Fixed in 42.5.2 - Upgrade
Upgrade
Electronto a version that resolves this vulnerability.Fixed in 43.0.0 - Configuration
Do not apply allow-popups to sandboxed iframes that render untrusted content.
Electron sandboxed iframes allow-popups = disabled - Configuration
Use setWindowOpenHandler on the parent WebContents to deny or constrain popups opened from sandboxed frames.
Electron WebContents setWindowOpenHandler = deny or constrain popups
Event History
Frequently Asked Questions
Which Electron applications are exposed to this issue?
Applications are affected only if they embed untrusted content in sandboxed iframes configured with both allow-scripts and allow-popups. Applications that do not embed untrusted content in sandboxed iframes are not affected.
What must an attacker do to exploit the vulnerability?
An attacker needs untrusted content to execute inside an affected sandboxed iframe and open a popup, such as through a target="_blank" link or a middle-click. The resulting popup can receive the embedding application's full origin rather than the iframe's sandbox restrictions.
What could a successful exploit allow?
The popup may gain access to the embedding application's cookies, storage, and same-origin scripting capabilities. This can expose data associated with the embedding application's origin and permit limited integrity impact.
What can be done if updating Electron is not immediately possible?
Use setWindowOpenHandler on the parent WebContents to deny or constrain popups opened from sandboxed frames. Alternatively, do not grant allow-popups to sandboxed iframes that render untrusted content.
Which Electron releases contain the fix?
The issue is fixed in Electron 43.0.0, 42.5.2, and 41.10.4.