CVE-2022-29257

MEDIUM

Electron <18.0.0-beta.6, 17.2.0, 16.2.6, 15.5.5 - Code Injection

Title source: llm
STIX 2.1

Description

Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 allows attackers who have control over a given apps update server / update storage to serve maliciously crafted update packages that pass the code signing validation check but contain malicious code in some components. This kind of attack would require significant privileges in a potential victim's own auto updating infrastructure and the ease of that attack entirely depends on the potential victim's infrastructure security. Electron versions 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 contain a fix for this issue. There are no known workarounds.

References (1)

Core 1
Core References

Scores

CVSS v3 6.6
EPSS 0.0045
EPSS Percentile 63.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20
Status published
Products (5)
electronjs/electron 16.0.0 beta1 (9 CPE variants)
electronjs/electron 17.0.0 beta1 (9 CPE variants)
electronjs/electron 18.0.0 beta1 (5 CPE variants)
electronjs/electron < 15.5.0
npm/electron 0 - 15.5.0npm
Published Jun 13, 2022
Tracked Since Feb 18, 2026