CVE-2020-4075

MEDIUM

Electron <7.2.4-9.0.0-beta21 - Local File Read

Title source: llm
STIX 2.1

Description

In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, arbitrary local file read is possible by defining unsafe window options on a child window opened via window.open. As a workaround, ensure you are calling `event.preventDefault()` on all new-window events where the `url` or `options` is not something you expect. This is fixed in versions 9.0.0-beta.21, 8.2.4 and 7.2.4.

References (2)

Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://www.electronjs.org/releases/stable?page=3#release-notes-for-v824

Scores

CVSS v3 6.8
EPSS 0.0118
EPSS Percentile 63.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N

Details

CWE
CWE-552
Status published
Products (3)
electronjs/electron 9.0.0 (21 CPE variants)
electronjs/electron 7.0.0 - 7.2.4
npm/electron 0 - 7.2.4npm
Published Jul 07, 2020
Tracked Since Feb 18, 2026