Sploitus

CVE-2017-12581

No indexed exploits for CVE-2017-12581 yet

GitHub Electron before 1.6.8 allows remote command execution because of a nodeIntegration bypass vulnerability. This also affects all applications that bundle Electron code equivalent to 1.6.8 or earlier. Bypassing the Same Origin Policy (SOP) is a precondition; however, recent Electron versions do not have strict SOP enforcement. Combining an SOP bypass with a privileged URL internally used by Electron, it was possible to execute native Node.js primitives in order to run OS commands on the user's host. Specifically, a chrome-devtools://devtools/bundled/inspector.html window could be used to eval a Node.js child_process.execFile API call.

Affected products
Electron
Electron
≤ 1.6.7
Fix
Available
CVSS 2.0
9.3 HIGH
CVSS 3.1
8.1 HIGH
EPSS
6.7% (93th percentile)
Weakness
CWE-78
NVD status
Modified
Published
2017-08-06
CVE-2017-12581 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2017-12581 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2017-12581 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.