CVE-2020-12079

CRITICAL

Beaker < 0.8.9 - Remote Code Execution via Prototype Pollution

Title source: llm
STIX 2.1

Description

Beaker before 0.8.9 allows a sandbox escape, enabling system access and code execution. This occurs because Electron context isolation is not used, and therefore an attacker can conduct a prototype-pollution attack against the Electron internal messaging API.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://github.com/beakerbrowser/beaker/issues/1519
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/beakerbrowser/beaker/releases/tag/0.8.9

Scores

CVSS v3 10.0
EPSS 0.0223
EPSS Percentile 80.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-1321
Status published
Products (1)
beakerbrowser/beaker < 0.8.9
Published Apr 23, 2020
Tracked Since Feb 18, 2026