CVE-2024-23755

HIGH

ClickUp Desktop < 3.3.77 - Code Injection via Electron Fuses

Title source: llm
STIX 2.1

Description

ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode.

Scores

CVSS v3 8.8
EPSS 0.0105
EPSS Percentile 60.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
clickup/clickup < 3.3.77
Published Mar 23, 2024
Tracked Since Feb 18, 2026