CVE-2022-29257
MEDIUMElectron <18.0.0-beta.6, 17.2.0, 16.2.6, 15.5.5 - Code Injection
Title source: llmDescription
Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 allows attackers who have control over a given apps update server / update storage to serve maliciously crafted update packages that pass the code signing validation check but contain malicious code in some components. This kind of attack would require significant privileges in a potential victim's own auto updating infrastructure and the ease of that attack entirely depends on the potential victim's infrastructure security. Electron versions 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 contain a fix for this issue. There are no known workarounds.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_confirm
https://github.com/electron/electron/security/advisories/GHSA-77xc-hjv8-ww97
Scores
CVSS v3
6.6
EPSS
0.0045
EPSS Percentile
63.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-20
Status
published
Products (5)
electronjs/electron
16.0.0 beta1 (9 CPE variants)
electronjs/electron
17.0.0 beta1 (9 CPE variants)
electronjs/electron
18.0.0 beta1 (5 CPE variants)
electronjs/electron
< 15.5.0
npm/electron
0 - 15.5.0npm
Published
Jun 13, 2022
Tracked Since
Feb 18, 2026