CVE-2024-23739

CRITICAL

Discord for macOS <0.0.291 - RCE

Title source: llm

Description

An issue in Discord for macOS version 0.0.291 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.

Exploits (2)

nomisec WRITEUP 3 stars
by giovannipajeu1 · poc
https://github.com/giovannipajeu1/CVE-2024-23739
inthewild WRITEUP
poc
https://github.com/v3x0r/cve-2024-23739

Scores

CVSS v3 9.8
EPSS 0.3577
EPSS Percentile 97.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
discord/discord < 0.0.291
Published Jan 28, 2024
Tracked Since Feb 18, 2026