{"id":"GHSA-8xwg-wv7v-4vqp","summary":"Electron Vulnerable to Code Execution by Re-Enabling Node.js Integration","details":"A vulnerability has been discovered which allows Node.js integration to be re-enabled in some Electron applications that disable it.\n\nFor the application to be impacted by this vulnerability it must meet all of these conditions\n\n- Runs on Electron 1.7, 1.8, or a 2.0.0-beta\n- Allows execution of arbitrary remote code\n- Disables Node.js integration\n- Does not explicitly declare webviewTag: false in its webPreferences\n- Does not enable the nativeWindowOption option\n- Does not intercept new-window events and manually override event.newGuest without using the supplied options tag\n\n\n## Recommendation\n\nUpdate to `electron` version 1.7.13, 1.8.4, or 2.0.0-beta.5 or later.\n\nIf you are unable to update your Electron version can mitigate the vulnerability with the following code.\n\n```js\napp.on('web-contents-created', (event, win) =\u003e {\n  win.on('new-window', (event, newURL, frameName, disposition,\n                        options, additionalFeatures) =\u003e {\n    if (!options.webPreferences) options.webPreferences = {};\n    options.webPreferences.nodeIntegration = false;\n    options.webPreferences.nodeIntegrationInWorker = false;\n    options.webPreferences.webviewTag = false;\n    delete options.webPreferences.preload;\n  })\n})\n\n// and *IF* you don't use WebViews at all,\n// you might also want\napp.on('web-contents-created', (event, win) =\u003e {\n  win.on('will-attach-webview', (event, webPreferences, params) =\u003e {\n    event.preventDefault();\n  })\n})\n```","aliases":["CVE-2018-1000136"],"modified":"2023-11-08T03:59:35.638763Z","published":"2018-03-26T16:41:17Z","database_specific":{"cwe_ids":["CWE-20"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:26:59Z","nvd_published_at":null},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000136"},{"type":"WEB","url":"https://github.com/electron/electron/pull/12271"},{"type":"WEB","url":"https://github.com/electron/electron/pull/12292"},{"type":"WEB","url":"https://github.com/electron/electron/pull/12294"},{"type":"WEB","url":"https://github.com/electron/electron/commit/1a48ee28276e6588dbf4e70e58d78e7bfdc57043"},{"type":"WEB","url":"https://electronjs.org/blog/webview-fix"},{"type":"PACKAGE","url":"https://github.com/electron/electron"},{"type":"WEB","url":"https://www.electronjs.org/blog/webview-fix"},{"type":"WEB","url":"https://www.npmjs.com/advisories/574"},{"type":"WEB","url":"https://www.trustwave.com/Resources/SpiderLabs-Blog/CVE-2018-1000136---Electron-nodeIntegration-Bypass"}],"affected":[{"package":{"name":"electron","ecosystem":"npm","purl":"pkg:npm/electron"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.7.0"},{"fixed":"1.7.13"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/03/GHSA-8xwg-wv7v-4vqp/GHSA-8xwg-wv7v-4vqp.json"}},{"package":{"name":"electron","ecosystem":"npm","purl":"pkg:npm/electron"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.8.0"},{"fixed":"1.8.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/03/GHSA-8xwg-wv7v-4vqp/GHSA-8xwg-wv7v-4vqp.json"}},{"package":{"name":"electron","ecosystem":"npm","purl":"pkg:npm/electron"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.0.0-beta.1"},{"fixed":"2.0.0-beta.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/03/GHSA-8xwg-wv7v-4vqp/GHSA-8xwg-wv7v-4vqp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}