Showing 1 vulnerability on this page for electron-builder

Signals CISA KEV Ransomware Nuclei
electron vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

electron-builder's NSIS installer - execute arbitrary code on the target machine (Windows only)

electron-builder is a solution to package and build a ready for distribution Electron, Proton Native app for macOS, Windows and Linux. A vulnerability that only affects eletron-builder prior to 24.13.2 in Windows, the NSIS installer makes a system call to open cmd.exe via NSExec in the `.nsh` installer script. NSExec by default searches the current directory of where the installer is located before searching `PATH`. This means that if an attacker can place a malicious executable file named cmd.e

CWE-426CWE-427Mar 6, 2024
CVSS7.3v3.1EPSS0.282%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX