{"id":"CVE-2024-29900","summary":"@electron/packager's build process memory potentially leaked into final executable","details":"Electron Packager bundles Electron-based application source code with a renamed Electron executable and supporting files into folders ready for distribution. A random segment of ~1-10kb of Node.js heap memory allocated either side of a known buffer will be leaked into the final executable. This memory _could_ contain sensitive information such as environment variables, secrets files, etc. This issue is patched in 18.3.1.\n","aliases":["GHSA-34h3-8mw4-qw57"],"modified":"2026-08-12T03:51:34.682747977Z","published":"2024-03-29T15:15:45.766Z","database_specific":{"cwe_ids":["CWE-402"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/29xxx/CVE-2024-29900.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/29xxx/CVE-2024-29900.json"},{"type":"ADVISORY","url":"https://github.com/electron/packager/security/advisories/GHSA-34h3-8mw4-qw57"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-29900"},{"type":"FIX","url":"https://github.com/electron/packager/commit/d421d4bd3ced889a4143c5c3ab6d95e3be249eee"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/electron/packager","events":[{"introduced":"224cc6a28ddfcf4d1a184a25d10833cf153e3bda"},{"fixed":"d421d4bd3ced889a4143c5c3ab6d95e3be249eee"}],"database_specific":{"extracted_events":[{"introduced":"18.3.0"},{"last_affected":"18.3.0"}],"source":["CPE_STRING","REFERENCES"],"cpe":"cpe:2.3:a:openjsf:packager:18.3.0:*:*:*:*:node.js:*:*"}}],"versions":["18.3.0","= 18.3.0","v18.3.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-29900.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}