{"id":"CVE-2023-49314","details":"Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode and EnableNodeCliInspectArguments, and thus r3ggi/electroniz3r can be used to perform an attack.","modified":"2026-08-12T03:51:41.172353526Z","published":"2023-11-28T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/49xxx/CVE-2023-49314.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://asana.com/pt/download"},{"type":"WEB","url":"https://www.electronjs.org/docs/latest/tutorial/fuses"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/49xxx/CVE-2023-49314.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-49314"},{"type":"PACKAGE","url":"https://github.com/electron/fuses"},{"type":"PACKAGE","url":"https://github.com/louiselalanne/CVE-2023-49314"},{"type":"PACKAGE","url":"https://github.com/r3ggi/electroniz3r"},{"type":"ARTICLE","url":"https://www.electronjs.org/blog/statement-run-as-node-cves"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/electron/fuses","events":[{"introduced":"c76019bb492b6a2ebbe9fc1fe07a970486729a27"},{"last_affected":"c76019bb492b6a2ebbe9fc1fe07a970486729a27"}],"database_specific":{"extracted_events":[{"introduced":"2.1.0"},{"last_affected":"2.1.0"}],"source":"CPE_STRING","cpe":"cpe:2.3:a:asana:desktop:2.1.0:*:*:*:*:*:*:*"}}],"versions":["2.1.0","v2.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-49314.json"}}],"schema_version":"1.9.0"}