{"id":"GHSA-gvcj-pfq2-wxj7","summary":"High severity vulnerability that affects electron","details":"Untrusted search path vulnerability in Atom Electron before 0.33.5 allows local users to gain privileges via a Trojan horse Node.js module in a parent directory of a directory named on a require line.","aliases":["CVE-2016-1202"],"modified":"2023-11-08T03:58:22.066587Z","published":"2017-10-24T18:33:35Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-06-16T21:38:05Z","nvd_published_at":null,"cwe_ids":["CWE-426"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-1202"},{"type":"WEB","url":"https://github.com/electron/electron/pull/2976"},{"type":"WEB","url":"https://github.com/electron/electron/commit/9a2e2b365d061ec10cd861391fd5b1344af7194d"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-gvcj-pfq2-wxj7"},{"type":"PACKAGE","url":"https://github.com/electron/electron"},{"type":"WEB","url":"http://jvn.jp/en/jp/JVN00324715/index.html"},{"type":"WEB","url":"http://jvndb.jvn.jp/jvndb/JVNDB-2016-000054"}],"affected":[{"package":{"name":"electron","ecosystem":"npm","purl":"pkg:npm/electron"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.33.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-gvcj-pfq2-wxj7/GHSA-gvcj-pfq2-wxj7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}