CVE-2023-49314

HIGH

Asana Desktop 2.1.0 - Code Injection

Title source: llm
STIX 2.1

Description

Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode and EnableNodeCliInspectArguments, and thus r3ggi/electroniz3r can be used to perform an attack.

Exploits (1)

nomisec WRITEUP 6 stars
by louiselalanne · poc
https://github.com/louiselalanne/CVE-2023-49314

Scores

CVSS v3 7.8
EPSS 0.1764
EPSS Percentile 95.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
asana/desktop 2.1.0
Published Nov 28, 2023
Tracked Since Feb 18, 2026