CVE-2017-12581
GitHub Electron before 1.6.8 allows remote command execution because of a nodeIntegration bypass vulnerability. This also affects all applications that bundle Electron code equivalent to 1.6.8 or earlier. Bypassing the Same Origin Policy (SOP) is a precondition; however, recent Electron versions do not have strict SOP enforcement. Combining an SOP bypass with a privileged URL internally used by Electron, it was possible to execute native Node.js primitives in order to run OS commands on the user's host. Specifically, a chrome-devtools://devtools/bundled/inspector.html window could be used to eval a Node.js child_process.execFile API call.
- Affected products
- Electron
- Electron
- ≤ 1.6.7
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- CVSS 3.1
- 8.1 HIGH
- EPSS
- 6.7% (93th percentile)
- Weakness
- CWE-78
- NVD status
- Modified
- Published
- 2017-08-06
No indexed exploits for CVE-2017-12581 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2017-12581 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.