<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Electron (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/electron.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/electron-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Electron (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:38 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-45668 – Trilium Notes is a cross-platform, hierarchical note taking application focused ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45668</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45668</guid>
    <pubDate>Fri, 29 May 2026 18:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45668</strong></p>
  <p>Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.102.2, a malicious ZIP archive imported with safe import enabled achieves RCE via #docName path traversal and XSS by combining a payload note (type: code, mime: text/plain) containing raw HTML/JS and a trigger note (type: doc or type: launcher) with a #docName lab…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45668">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39310 – Trilium Notes is a cross-platform, hierarchical note taking application focused ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39310</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39310</guid>
    <pubDate>Wed, 20 May 2026 20:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39310</strong></p>
  <p>Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Clipper API in Trilium Desktop (v0.101.3) allows full authentication bypass when running in an Electron environment. When Trilium detects an Electron environment, it explicitly disables authentication middleware for the Clipper API, exposin…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39310">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26462 – Offline Hospital Management System 5.3.0 allows remote code execution due to an ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26462</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26462</guid>
    <pubDate>Mon, 18 May 2026 15:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26462</strong></p>
  <p>Offline Hospital Management System 5.3.0 allows remote code execution due to an improper Electron renderer configuration. The application enables Node.js integration while disabling context isolation, allowing JavaScript executed in the renderer process to access Node.js APIs and execute arbitrary operating system commands.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-917</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26462">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44670 – SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44670</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44670</guid>
    <pubDate>Thu, 14 May 2026 19:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44670</strong></p>
  <p>SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the kernel stores Attribute View (AV / database) names without any HTML escape, then a render template uses raw strings.ReplaceAll(tpl, "${avName}", nodeAvName) to embed the name in HTML before pushing to all clients via WebSocket. Three independent client paths (render.ts:120 → outerHTML, Title.ts:401 → innerHTML, tra…</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44670">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44588 – SiYuan is an open-source personal knowledge management system. Prior to 3.7.0,  ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44588</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44588</guid>
    <pubDate>Thu, 14 May 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44588</strong></p>
  <p>SiYuan is an open-source personal knowledge management system. Prior to 3.7.0,  he tooltip mouseover handler in app/src/block/popover.ts reads aria-label via getAttribute and passes it through decodeURIComponent before assigning to messageElement.innerHTML in app/src/dialog/tooltip.ts:41. The encoder used at the producer side, escapeAriaLabel in app/src/util/escape.ts:19-25, only handles HTML spe…</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44588">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44586 – SiYuan is an open-source personal knowledge management system. From 2.1.12 to be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44586</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44586</guid>
    <pubDate>Thu, 14 May 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44586</strong></p>
  <p>SiYuan is an open-source personal knowledge management system. From 2.1.12 to before 3.7.0. SiYuan's Bazaar marketplace renders package author metadata from the public bazaar stage feed into HTML without escaping. In the desktop app this becomes stored XSS, and because SiYuan's Electron windows are created with nodeIntegration: true and contextIsolation: false, a successful payload can call Node.…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44586">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44482 – soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Las...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44482</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44482</guid>
    <pubDate>Thu, 14 May 2026 15:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44482</strong></p>
  <p>soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. Prior to 0.1.8, a track title containing an HTML payload executed locally in the Electron app. This means attacker-controlled SoundCloud track metadata can lead to local command execution on the user's machine. The application exposes a preload API (window.soundcloudAPI.sendTrackUpdate) to th…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44482">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-43899 – DeepChat is an open-source artificial intelligence agent platform that unifies m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43899</guid>
    <pubDate>Mon, 11 May 2026 23:20:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-43899</strong></p>
  <p>DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, An incomplete mitigation for CVE-2025-55733 leaves DeepChat vulnerable to an arbitrary protocol execution bypass (RCE). While the patch correctly restricted api.openExternal() inside the renderer's preload/index.ts script, it structurally neglected to sanitize native E…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42090 – Notesnook is a note-taking app focused on user privacy &amp; ease of use. Prior to N...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42090</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42090</guid>
    <pubDate>Mon, 04 May 2026 17:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42090</strong></p>
  <p>Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Android version 3.3.20, a stored XSS vulnerability in the note export flow can be escalated to remote code execution in the desktop app. The root cause is that exported note fields such as title, headline, and content are inserted into the generated HTML t…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42090">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41421 – SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41421</guid>
    <pubDate>Fri, 24 Apr 2026 19:17:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41421</strong></p>
  <p>SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, SiYuan desktop renders notification messages as raw HTML inside an Electron renderer. The notification route POST /api/notification/pushMsg accepts a user-controlled msg value, forwards it through the backend broadcast layer, and the frontend inserts it into the DOM with insertAdjacentHTML(...) at message.ts. On deskto…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40322 – SiYuan is an open-source personal knowledge management system. In versions 3.6.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40322</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40322</guid>
    <pubDate>Thu, 16 Apr 2026 23:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40322</strong></p>
  <p>SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendered with securityLevel set to "loose", and the resulting SVG is injected into the DOM via innerHTML. This allows attacker-controlled javascript: URLs in Mermaid code blocks to survive into the rendered output. On desktop builds using Electron, windows are created with nodeIntegrat…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40322">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-39846 – SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious no...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39846</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39846</guid>
    <pubDate>Tue, 07 Apr 2026 22:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-39846</strong></p>
  <p>SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is that table caption content is stored without safe escaping and later unescaped into rendered HTML, creating a stored XSS sink. Because the desktop renderer runs with nodeIntegration enabled and contextI…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39846">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34780 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34780</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34780</guid>
    <pubDate>Sat, 04 Apr 2026 01:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34780</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39.0.0-alpha.1 to before 39.8.0, 40.0.0-alpha.1 to before 40.7.0, and 41.0.0-alpha.1 to before 41.0.0-beta.8, apps that pass VideoFrame objects (from the WebCodecs API) across the contextBridge are vulnerable to a context isolation bypass. An attacker who can execute JavaScript in…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34780">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34774 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34774</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34774</guid>
    <pubDate>Sat, 04 Apr 2026 00:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34774</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 39.8.1, 40.7.0, and 41.0.0, apps that use offscreen rendering and allow child windows via window.open() may be vulnerable to a use-after-free. If the parent offscreen WebContents is destroyed while a child window remains open, subsequent paint frames on the child dereference f…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34774">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34771 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34771</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34771</guid>
    <pubDate>Sat, 04 Apr 2026 00:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34771</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that register an asynchronous session.setPermissionRequestHandler() may be vulnerable to a use-after-free when handling fullscreen, pointer-lock, or keyboard-lock permission requests. If the requesting frame navigates or the wind…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34771">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34770 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34770</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34770</guid>
    <pubDate>Sat, 04 Apr 2026 00:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34770</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, apps that use the powerMonitor module may be vulnerable to a use-after-free. After the native PowerMonitor object is garbage-collected, the associated OS-level resources (a message window on Windows, a shutdown handler on macOS) retai…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34770">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34769 – Electron is a framework for writing cross-platform desktop applications using Ja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34769</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34769</guid>
    <pubDate>Sat, 04 Apr 2026 00:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34769</strong></p>
  <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, an undocumented commandLineSwitches webPreference allowed arbitrary switches to be appended to the renderer process command line. Apps that construct webPreferences by spreading untrusted configuration objects may inadvertently allow…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34769">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34725 – DbGate is cross-platform database manager. From version 7.0.0 to before version ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34725</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34725</guid>
    <pubDate>Thu, 02 Apr 2026 18:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34725</strong></p>
  <p>DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS vulnerability exists in DbGate because attacker-controlled SVG icon strings are rendered as raw HTML without sanitization. In the web UI this allows script execution in another user's browser; in the Electron desktop app this can escalate to local code execution because Electron is configured with…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34725">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34585 – SiYuan is a personal knowledge management system. Prior to version 3.6.2, a vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34585</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34585</guid>
    <pubDate>Tue, 31 Mar 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34585</strong></p>
  <p>SiYuan is a personal knowledge management system. Prior to version 3.6.2, a vulnerability allows crafted block attribute values to bypass server-side attribute escaping when an HTML entity is mixed with raw special characters. An attacker can embed a malicious IAL value inside a .sy document, package it as a .sy.zip, and have the victim import it through the normal Import -> SiYuan .sy.zip workfl…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34585">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34449 – SiYuan is a personal knowledge management system. Prior to version 3.6.2, a mali...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34449</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34449</guid>
    <pubDate>Tue, 31 Mar 2026 22:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34449</strong></p>
  <p>SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code Execution (RCE) on any desktop running SiYuan by exploiting the permissive CORS policy (Access-Control-Allow-Origin: * + Access-Control-Allow-Private-Network: true) to inject a JavaScript snippet via the API. The injected snippet executes in Electron's Node.js context with full OS…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-942</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34449">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34448 – SiYuan is a personal knowledge management system. Prior to version 3.6.2, an att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34448</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34448</guid>
    <pubDate>Tue, 31 Mar 2026 22:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34448</strong></p>
  <p>SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field can trigger stored XSS when a victim opens the Gallery or Kanban view with “Cover From -> Asset Field” enabled. The vulnerable code accepts arbitrary http(s) URLs without extensions as images, stores the attacker-controlled string in coverURL, and in…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34448">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33976 – Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33976</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33976</guid>
    <pubDate>Fri, 27 Mar 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33976</strong></p>
  <p>Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can be escalated to remote code execution in the desktop app. The root cause is that the clipper preserves attacker-controlled attributes from the source page’s root element and stores them inside web-clip HTML. When the clip is later opened, Notesnook r…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33976">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33955 – Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33955</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33955</guid>
    <pubDate>Fri, 27 Mar 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33955</strong></p>
  <p>Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison viewer can escalate to remote code execution in a desktop application. The issue is triggered when an attacker-controlled note header is displayed using `dangerouslySetInnerHTML` without secure handling. When combined with the full backup and restore f…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33955">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33336 – Vikunja is an open-source self-hosted task management platform. Starting in vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33336</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33336</guid>
    <pubDate>Tue, 24 Mar 2026 16:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33336</strong></p>
  <p>Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper enables `nodeIntegration` in the main BrowserWindow and does not restrict same-window navigations. An attacker who can place a link in user-generated content (task descriptions, comments, project descriptions) can cause the BrowserWindow to na…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33336">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33335 – Vikunja is an open-source self-hosted task management platform. Starting in vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33335</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33335</guid>
    <pubDate>Tue, 24 Mar 2026 16:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33335</strong></p>
  <p>Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper passes URLs from `window.open()` calls directly to `shell.openExternal()` without any validation or protocol allowlisting. An attacker who can place a link with `target="_blank"` (or that otherwise triggers `window.open`) in user-generated con…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-939</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33335">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33334 – Vikunja is an open-source self-hosted task management platform. Starting in vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33334</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33334</guid>
    <pubDate>Tue, 24 Mar 2026 16:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33334</strong></p>
  <p>Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper enables `nodeIntegration` in the renderer process without `contextIsolation` or `sandbox`. This means any cross-site scripting (XSS) vulnerability in the Vikunja web frontend -- present or future -- automatically escalates to full remote code…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33334">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33067 – SiYuan is a personal knowledge management system. Versions 3.6.0 and below rende...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33067</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33067</guid>
    <pubDate>Fri, 20 Mar 2026 09:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33067</strong></p>
  <p>SiYuan is a personal knowledge management system. Versions 3.6.0 and below render package metadata fields (displayName, description) using template literals without HTML escaping. A malicious package author can inject arbitrary HTML/JavaScript into these fields, which executes automatically when any user browses the Bazaar page. Because SiYuan's Electron configuration enables nodeIntegration: tru…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33067">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33066 – SiYuan is a personal knowledge management system. In versions 3.6.0 and below, t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33066</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33066</guid>
    <pubDate>Fri, 20 Mar 2026 09:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33066</strong></p>
  <p>SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the backend renderREADME function uses lute.New() without calling SetSanitize(true), allowing raw HTML embedded in Markdown to pass through unmodified. The frontend then assigns the rendered HTML to innerHTML without any additional sanitization. A malicious package author can embed arbitrary JavaScript in their README…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33066">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-32751 – SiYuan is a personal knowledge management system. In versions 3.6.0 and below, t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32751</guid>
    <pubDate>Thu, 19 Mar 2026 22:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-32751</strong></p>
  <p>SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the mobile file tree (MobileFiles.ts) renders notebook names via innerHTML without HTML escaping when processing renamenotebook WebSocket events. The desktop version (Files.ts) properly uses escapeHtml() for the same operation. An authenticated user who can rename notebooks can inject arbitrary HTML/JavaScript that exe…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-32626 – AnythingLLM is an application that turns pieces of content into context that any...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32626</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32626</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-32626</strong></p>
  <p>AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, AnythingLLM Desktop contains a Streaming Phase XSS vulnerability in the chat rendering pipeline that escalates to Remote Code Execution on the host OS due to insecure Electron configuration. This works with default settings and requires no user interac…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32626">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-22793 – 5ire is a cross-platform desktop artificial intelligence assistant and model con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22793</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22793</guid>
    <pubDate>Wed, 21 Jan 2026 21:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-22793</strong></p>
  <p>5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe option parsing vulnerability in the ECharts Markdown plugin allows any user able to submit ECharts code blocks to execute arbitrary JavaScript code in the renderer context. This can lead to Remote Code Execution (RCE) in environments where privileged APIs (such…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22793">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14498 – TradingView Desktop Electron Uncontrolled Search Path Local Privilege Escalation...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14498</guid>
    <pubDate>Tue, 23 Dec 2025 22:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14498</strong></p>
  <p>TradingView Desktop Electron Uncontrolled Search Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of TradingView Desktop. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.  The specific flaw exists within the configuration of…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-67744 – DeepChat is an open-source artificial intelligence agent platform that unifies m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67744</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67744</guid>
    <pubDate>Tue, 16 Dec 2025 01:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-67744</strong></p>
  <p>DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to version 0.5.3, a security vulnerability exists in the Mermaid diagram rendering component that allows arbitrary JavaScript execution. Due to the exposure of the Electron IPC renderer to the DOM, this Cross-Site Scripting (XSS) flaw escalates to full Remote Code Execution (RCE), allow…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67744">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-66481 – DeepChat is an open-source AI chat platform that supports cloud models and LLMs...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66481</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66481</guid>
    <pubDate>Tue, 09 Dec 2025 01:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-66481</strong></p>
  <p>DeepChat is an open-source AI chat platform that supports cloud models and LLMs. Versions 0.5.1 and below are vulnerable to XSS attacks through improperly sanitized Mermaid content. The recent security patch for MermaidArtifact.vue is insufficient and can be bypassed using unquoted HTML attributes combined with HTML entity encoding. Remote Code Execution is possible on the victim's machine via th…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66481">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-66222 – DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66222</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66222</guid>
    <pubDate>Wed, 03 Dec 2025 19:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-66222</strong></p>
  <p>DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting (XSS) vulnerability in the Mermaid diagram renderer allows an attacker to execute arbitrary JavaScript within the application context. By leveraging the exposed Electron IPC bridge, this XSS can be escalated to Remote Code Execution (RCE) by registering and starting a malicious…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66222">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-51387 – The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-51387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-51387</guid>
    <pubDate>Mon, 04 Aug 2025 21:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-51387</strong></p>
  <p>The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifically, the following insecure settings were observed: RunAsNode is enabled and EnableNodeCliInspectArguments is not disabled. These configurations allow the application to be executed in Node.js mode, enabling attackers to pass arguments that result in arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-51387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-46992 – Electron is an open source framework for writing cross-platform desktop applicat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46992</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46992</guid>
    <pubDate>Tue, 01 Jul 2025 02:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-46992</strong></p>
  <p>Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 30.0.0-alpha.1 to before 30.0.5 and 31.0.0-alpha.1 to before 31.0.0-beta.1, Electron is vulnerable to an ASAR Integrity bypass. This only impacts apps that have the embeddedAsarIntegrityValidation and onlyLoadAppFromAsar fuses enabled. Apps without these fuses enabled…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-354</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46992">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-57783 – The desktop application in Dot through 0.9.3 allows XSS and resultant command ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-57783</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-57783</guid>
    <pubDate>Mon, 02 Jun 2025 14:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-57783</strong></p>
  <p>The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-57783">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-47777 – 5ire is a cross-platform desktop artificial intelligence assistant and model con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47777</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47777</guid>
    <pubDate>Wed, 14 May 2025 16:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-47777</strong></p>
  <p>5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Versions prior to 0.11.1 are vulnerable to stored cross-site scripting in chatbot responses due to insufficient sanitization. This, in turn, can lead to Remote Code Execution (RCE) via unsafe Electron protocol handling and exposed Electron APIs. All users of 5ire client versions prior to patched…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47777">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-57061 – An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-57061</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-57061</guid>
    <pubDate>Wed, 19 Mar 2025 19:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-57061</strong></p>
  <p>An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via the insecure Electron Fuses configuration.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-57061">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-22136 – Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22136</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22136</guid>
    <pubDate>Wed, 08 Jan 2025 16:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-22136</strong></p>
  <p>Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.217 , Tabby enables several high-risk Electron Fuses, including RunAsNode, EnableNodeCliInspectArguments, and EnableNodeOptionsEnvironmentVariable. These fuses create potential code injection vectors even though the application is signed with hardened runtime and lacks dangerous entitlements such as com.apple.secur…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22136">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-49362 – Joplin is a free, open source note taking and to-do application. Joplin-desktop ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49362</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49362</guid>
    <pubDate>Thu, 14 Nov 2024 18:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-49362</strong></p>
  <p>Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote code execution (RCE) when a user clicks on an <a> link within untrusted notes. The issue arises due to insufficient sanitization of <a> tag attributes introduced by the Mermaid. This vulnerability allows the execution of untrusted HTML content within the Electron window, which…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49362">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-8258 – Improper Control of Generation of Code ('Code Injection') in Electron Fuses in L...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8258</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8258</guid>
    <pubDate>Tue, 10 Sep 2024 09:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-8258</strong></p>
  <p>Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to execute arbitrary code via insecure Electron Fuses configuration.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8258">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22169 – WD Discovery
versions prior to 5.0.589 contain a misconfiguration in the Node.js...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22169</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22169</guid>
    <pubDate>Fri, 02 Aug 2024 19:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22169</strong></p>
  <p>WD Discovery versions prior to 5.0.589 contain a misconfiguration in the Node.js environment settings that could allow code execution by utilizing the 'ELECTRON_RUN_AS_NODE' environment variable. Any malicious application operating with standard user permissions can exploit this vulnerability, enabling code execution within WD Discovery application's context. WD Discovery version 5.0.589 addresse…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22169">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39698 – electron-updater allows for automatic updates for Electron apps. The file `packa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39698</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39698</guid>
    <pubDate>Tue, 09 Jul 2024 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39698</strong></p>
  <p>electron-updater allows for automatic updates for Electron apps. The file `packages/electron-updater/src/windowsExecutableCodeSignatureVerifier.ts` implements the signature validation routine for Electron applications on Windows. Because of the surrounding shell, a first pass by `cmd.exe` expands any environment variable found in command-line above. This creates a situation where `verifySignature…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-154</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39698">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-23997 – Lukas Bach yana =&lt;1.0.16 is vulnerable to Cross Site Scripting (XSS) via src/ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23997</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23997</guid>
    <pubDate>Fri, 05 Jul 2024 16:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-23997</strong></p>
  <p>Lukas Bach yana =<1.0.16 is vulnerable to Cross Site Scripting (XSS) via src/electron-main.ts.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23997">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-39517 – Joplin is a free, open source note taking and to-do application. A Cross site sc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39517</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39517</guid>
    <pubDate>Fri, 21 Jun 2024 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-39517</strong></p>
  <p>Joplin is a free, open source note taking and to-do application. A Cross site scripting (XSS) vulnerability in affected versions allows clicking on an untrusted image link to execute arbitrary shell commands. The HTML sanitizer (`packages/renderer/htmlUtils.ts::sanitizeHtml`) preserves `<map>` `<area>` links. However, unlike `<a>` links, the `target` and `href` attributes are not removed. Additio…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39517">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-3166 – A Cross-Site Scripting (XSS) vulnerability exists in mintplex-labs/anything-llm,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3166</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3166</guid>
    <pubDate>Thu, 06 Jun 2024 19:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-3166</strong></p>
  <p>A Cross-Site Scripting (XSS) vulnerability exists in mintplex-labs/anything-llm, affecting both the desktop application version 1.2.0 and the latest version of the web application. The vulnerability arises from the application's feature to fetch and embed content from websites into workspaces, which can be exploited to execute arbitrary JavaScript code. In the desktop application, this flaw can b…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3166">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-29900 – Electron Packager bundles Electron-based application source code with a renamed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-29900</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-29900</guid>
    <pubDate>Fri, 29 Mar 2024 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-29900</strong></p>
  <p>Electron Packager bundles Electron-based application source code with a renamed Electron executable and supporting files into folders ready for distribution. A random segment of ~1-10kb of Node.js heap memory allocated either side of a known buffer will be leaked into the final executable. This memory _could_ contain sensitive information such as environment variables, secrets files, etc. This is…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-402</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-29900">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23755 – ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23755</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23755</guid>
    <pubDate>Sat, 23 Mar 2024 22:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23755</strong></p>
  <p>ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23755">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-27303 – electron-builder is a solution to package and build a ready for distribution Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27303</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27303</guid>
    <pubDate>Wed, 06 Mar 2024 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27303</strong></p>
  <p>electron-builder is a solution to package and build a ready for distribution Electron, Proton Native app for macOS, Windows and Linux. A vulnerability that only affects eletron-builder prior to 24.13.2 in Windows, the NSIS installer makes a system call to open cmd.exe via NSExec in the `.nsh` installer script. NSExec by default searches the current directory of where the installer is located befo…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27303">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-50975 – The TD Bank TD Advanced Dashboard client through 3.0.3 for macOS allows arbitrar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50975</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50975</guid>
    <pubDate>Wed, 21 Feb 2024 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-50975</strong></p>
  <p>The TD Bank TD Advanced Dashboard client through 3.0.3 for macOS allows arbitrary code execution because of the lack of electron::fuses::IsRunAsNodeEnabled (i.e., ELECTRON_RUN_AS_NODE can be used in production). This makes it easier for a compromised process to access banking information.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50975">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-7245 – The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-7245</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-7245</guid>
    <pubDate>Tue, 20 Feb 2024 11:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-7245</strong></p>
  <p>The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute arbitrary code within the nodejs process context via the ELECTRON_RUN_AS_NODE environment variable</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-95</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-7245">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-1648 – electron-pdf version 20.0.0 allows an external attacker to remotely obtain

arbi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1648</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1648</guid>
    <pubDate>Tue, 20 Feb 2024 01:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-1648</strong></p>
  <p>electron-pdf version 20.0.0 allows an external attacker to remotely obtain  arbitrary local files. This is possible because the application does not  validate the HTML content entered by the user.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1648">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-23746 – Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23746</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23746</guid>
    <pubDate>Fri, 02 Feb 2024 02:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-23746</strong></p>
  <p>Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in some environments (bypass a kTCCServiceSystemPolicyAppBundles requirement via a file copy, an app.app/Contents rename, an asar modification, and a rename back to app.app/Contents).</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23746">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21625 – SideQuest is a place to get virtual reality applications for Oculus Quest. The S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21625</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21625</guid>
    <pubDate>Thu, 04 Jan 2024 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21625</strong></p>
  <p>SideQuest is a place to get virtual reality applications for Oculus Quest. The SideQuest desktop application uses deep links with a custom protocol (`sidequest://`) to trigger actions in the application from its web contents. Because, prior to version 0.10.35, the deep link URLs were not sanitized properly in all cases, a one-click remote code execution can be achieved in cases when a device is c…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21625">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-49314 – Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49314</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49314</guid>
    <pubDate>Tue, 28 Nov 2023 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-49314</strong></p>
  <p>Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode and EnableNodeCliInspectArguments, and thus r3ggi/electroniz3r can be used to perform an attack.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49314">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-42222 – WebCatalog before 49.0 is vulnerable to Incorrect Access Control. WebCatalog cal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-42222</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-42222</guid>
    <pubDate>Thu, 28 Sep 2023 03:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-42222</strong></p>
  <p>WebCatalog before 49.0 is vulnerable to Incorrect Access Control. WebCatalog calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42222">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-23623 – Electron is a framework which lets you write cross-platform desktop applications...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23623</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23623</guid>
    <pubDate>Wed, 06 Sep 2023 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-23623</strong></p>
  <p>Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. A Content-Security-Policy that disables eval, specifically setting a `script-src` directive and _not_ providing `unsafe-eval` in that directive, is not respected in renderers that have sandbox disabled.  i.e. `sandbox: false` in the `webPreferences` object. This allows usage of methods…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-670</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23623">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-48483 – 3CX before 18 Hotfix 1 build 18.0.3.461 on Windows allows unauthenticated remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-48483</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-48483</guid>
    <pubDate>Tue, 02 May 2023 05:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-48483</strong></p>
  <p>3CX before 18 Hotfix 1 build 18.0.3.461 on Windows allows unauthenticated remote attackers to read %WINDIR%\system32 files via /Electron/download directory traversal in conjunction with a path component that has a drive letter and uses backslash characters. NOTE: this issue exists because of an incomplete fix for CVE-2022-28005.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-48483">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-48482 – 3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-48482</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-48482</guid>
    <pubDate>Tue, 02 May 2023 05:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-48482</strong></p>
  <p>3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certain files via /Electron/download directory traversal. Files may have credentials, full backups, call recordings, and chat logs.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-48482">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-29059 – 3CX DesktopApp through 18.12.416 has embedded malicious code, as exploited in th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29059</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29059</guid>
    <pubDate>Thu, 30 Mar 2023 17:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-29059</strong></p>
  <p>3CX DesktopApp through 18.12.416 has embedded malicious code, as exploited in the wild in March 2023. This affects versions 18.12.407 and 18.12.416 of the 3CX DesktopApp Electron Windows application shipped in Update 7, and versions 18.11.1213, 18.12.402, 18.12.407, and 18.12.416 of the 3CX DesktopApp Electron macOS application.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29059">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-25908 – All versions of the package create-choo-electron are vulnerable to Command Injec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-25908</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-25908</guid>
    <pubDate>Thu, 26 Jan 2023 21:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-25908</strong></p>
  <p>All versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall  function due to improper user-input sanitization.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25908">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41957 – Muhammara is a node module with c/cpp bindings to modify PDF with JavaScript for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41957</guid>
    <pubDate>Mon, 28 Nov 2022 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41957</strong></p>
  <p>Muhammara is a node module with c/cpp bindings to modify PDF with JavaScript for node or electron. The package muhammara before 2.6.2 and from 3.0.0 and before 3.3.0, as well as all versions of muhammara's predecessor package hummus, are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be parsed. The issue has been patched in muhammara version 3.4.0 and t…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-690</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-36077 – The Electron framework enables writing cross-platform desktop applications using...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36077</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36077</guid>
    <pubDate>Tue, 08 Nov 2022 07:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-36077</strong></p>
  <p>The Electron framework enables writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 21.0.0-beta.1, 20.0.1, 19.0.11, and 18.3.7, Electron is vulnerable to Exposure of Sensitive Information. When following a redirect, Electron delays a check for redirecting to file:// URLs from other schemes. The contents of the file is not available to the renderer follo…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36077">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-39381 – Muhammara is a node module with c/cpp bindings to modify PDF with js for node or...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39381</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39381</guid>
    <pubDate>Wed, 02 Nov 2022 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-39381</strong></p>
  <p>Muhammara is a node module with c/cpp bindings to modify PDF with js for node or electron (based/replacement on/of galkhana/hummusjs). The package muhammara before 2.6.0; all versions of package hummus are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be appended to another. This issue has been patched in 2.6.0 for muhammara and not at all for hummus.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-690</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39381">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36668 – URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36668</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36668</guid>
    <pubDate>Tue, 12 Jul 2022 14:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36668</strong></p>
  <p>URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parameter to the Electron App.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36668">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-28005 – An issue was discovered in the 3CX Phone System Management Console prior to vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-28005</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-28005</guid>
    <pubDate>Fri, 06 May 2022 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-28005</strong></p>
  <p>An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticated attacker could abuse improperly secured access to arbitrary files on the server (via /Electron/download directory traversal in conjunction with a path component that uses backslash characters), leading to cleartext credential disclosure. Afterwards, the authenticated attacker…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28005">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-44042 – An issue was discovered in UiPath Assistant 21.4.4. User-controlled data supplie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-44042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-44042</guid>
    <pubDate>Tue, 14 Dec 2021 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-44042</strong></p>
  <p>An issue was discovered in UiPath Assistant 21.4.4. User-controlled data supplied to the --process-start argument of the URI handler for uipath-assistant:// is not correctly encoded, resulting in attacker-controlled content being injected into the error message displayed (when the injected content does not match an existing process). A determined attacker could leverage this to execute JavaScript…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-41392 – static/main-preload.js in Boost Note through 0.22.0 allows remote command execut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41392</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41392</guid>
    <pubDate>Fri, 17 Sep 2021 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-41392</strong></p>
  <p>static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal Electron API.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41392">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32772 – Poddycast is a podcast app made with Electron. Prior to version 0.8.1, an attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32772</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32772</guid>
    <pubDate>Tue, 03 Aug 2021 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32772</strong></p>
  <p>Poddycast is a podcast app made with Electron. Prior to version 0.8.1, an attacker can create a podcast or episode with malicious characters and execute commands on the client machine. The application does not clean the HTML characters of the podcast information obtained from the Feed, which allows the injection of HTML and JS code (cross-site scripting). Being an application made in electron, cr…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32772">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-25989 – Privilege escalation via arbitrary file write in pritunl electron client 1.0.111...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25989</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25989</guid>
    <pubDate>Thu, 19 Nov 2020 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-25989</strong></p>
  <p>Privilege escalation via arbitrary file write in pritunl electron client 1.0.1116.6 through v1.2.2550.20. Successful exploitation of the issue may allow an attacker to execute code on the effected system with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25989">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15174 – In Electron before versions 11.0.0-beta.1, 10.0.1, 9.3.0 or 8.5.1 the `will-navi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15174</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15174</guid>
    <pubDate>Tue, 06 Oct 2020 18:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15174</strong></p>
  <p>In Electron before versions 11.0.0-beta.1, 10.0.1, 9.3.0 or 8.5.1 the `will-navigate` event that apps use to prevent navigations to unexpected destinations as per our security recommendations can be bypassed when a sub-frame performs a top-frame navigation across sites. The issue is patched in versions 11.0.0-beta.1, 10.0.1, 9.3.0 or 8.5.1 As a workaround sandbox all your iframes using the sandbo…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15174">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-1889 – A security feature bypass issue in WhatsApp Desktop versions prior to v0.3.4932 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1889</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1889</guid>
    <pubDate>Thu, 03 Sep 2020 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-1889</strong></p>
  <p>A security feature bypass issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed for sandbox escape in Electron and escalation of privilege if combined with a remote code execution vulnerability inside the sandboxed renderer process.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-265</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1889">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-25019 – jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron sh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25019</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25019</guid>
    <pubDate>Sat, 29 Aug 2020 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-25019</strong></p>
  <p>jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25019">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4077 – In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4077</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4077</guid>
    <pubDate>Tue, 07 Jul 2020 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4077</strong></p>
  <p>In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions. Apps using both `contextIsolation` and `contextBridge` are affected. This is fixed in versions 9.0.0-beta.21, 8.2.4 and 7.2.4.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-501</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4077">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4076 – In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4076</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4076</guid>
    <pubDate>Tue, 07 Jul 2020 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4076</strong></p>
  <p>In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions. Apps using contextIsolation are affected. This is fixed in versions 9.0.0-beta.21, 8.2.4 and 7.2.4.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-501</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4076">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-12079 – Beaker before 0.8.9 allows a sandbox escape, enabling system access and code exe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12079</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12079</guid>
    <pubDate>Thu, 23 Apr 2020 04:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-12079</strong></p>
  <p>Beaker before 0.8.9 allows a sandbox escape, enabling system access and code execution. This occurs because Electron context isolation is not used, and therefore an attacker can conduct a prototype-pollution attack against the Electron internal messaging API.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-1321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12079">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-3582 – A Cross-site Request Forgery (CSRF) vulnerability exists in Advanced Electron Fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-3582</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-3582</guid>
    <pubDate>Wed, 22 Jan 2020 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-3582</strong></p>
  <p>A Cross-site Request Forgery (CSRF) vulnerability exists in Advanced Electron Forums (AEF) through 1.0.9 due to inadequate confirmation for sensitive transactions in the administrator functions.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-3582">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-20374 – A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20374</guid>
    <pubDate>Thu, 09 Jan 2020 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-20374</strong></p>
  <p>A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution through Mermaid code blocks. To exploit this vulnerability, one must open a file in Typora. The XSS vulnerability is then triggered due to improper HTML sanitization. Given that the application is based on the Electron framework, the XSS leads to remote code…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20374">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-17625 – There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17625</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17625</guid>
    <pubDate>Wed, 16 Oct 2019 12:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-17625</strong></p>
  <p>There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occurs due to incorrect sanitization of the name field when being processed and stored. This allows a user to craft a payload for Node.js and Electron, such as an exec of OS commands within the onerror attribute of an IMG element.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17625">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-15685 – GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios inv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-15685</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-15685</guid>
    <pubDate>Thu, 23 Aug 2018 05:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-15685</strong></p>
  <p>GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true" options, is affected by a WebPreferences vulnerability that can be leveraged to perform remote code execution.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-1188</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-15685">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-16151 – Based on details posted by the ElectronJS team; A remote code execution vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-16151</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-16151</guid>
    <pubDate>Thu, 07 Jun 2018 02:29:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-16151</strong></p>
  <p>Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects all recent versions of Electron. Any Electron app that accesses remote content is vulnerable to this exploit, regardless of whether the [sandbox option](https://electron.atom.io/docs/api/sandbox-option) is enabled.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-16151">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1000136 – Electron version 1.7 up to 1.7.12; 1.8 up to 1.8.3 and 2.0.0 up to 2.0.0-beta.3 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000136</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000136</guid>
    <pubDate>Fri, 23 Mar 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1000136</strong></p>
  <p>Electron version 1.7 up to 1.7.12; 1.8 up to 1.8.3 and 2.0.0 up to 2.0.0-beta.3 contains an improper handling of values vulnerability in Webviews that can result in remote code execution. This attack appear to be exploitable via an app which allows execution of 3rd party code AND disallows node integration AND has not specified if webview is enabled/disabled. This vulnerability appears to have be…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000136">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1000118 – Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Inj...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000118</guid>
    <pubDate>Wed, 07 Mar 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1000118</strong></p>
  <p>Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler that can result in command execute. This attack appear to be exploitable via the victim opening an electron protocol handler in their browser. This vulnerability appears to have been fixed in Electron 1.8.2-beta.5. This issue is due to an incomplete fix for CVE-2018-1000006, sp…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1000006 – GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000006</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000006</guid>
    <pubDate>Wed, 24 Jan 2018 23:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1000006</strong></p>
  <p>GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically Electron apps running on Windows 10, 7 or 2008 that register custom protocol handlers can be tricked in arbitrary command execution if the user clicks on a specially crafted URL. This has been fixed in versions 1.8.2-beta.4, 1.7.11, and 1.6.16.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000006">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-12581 – GitHub Electron before 1.6.8 allows remote command execution because of a nodeIn...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-12581</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-12581</guid>
    <pubDate>Sun, 06 Aug 2017 02:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-12581</strong></p>
  <p>GitHub Electron before 1.6.8 allows remote command execution because of a nodeIntegration bypass vulnerability. This also affects all applications that bundle Electron code equivalent to 1.6.8 or earlier. Bypassing the Same Origin Policy (SOP) is a precondition; however, recent Electron versions do not have strict SOP enforcement. Combining an SOP bypass with a privileged URL internally used by E…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12581">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-1202 – Untrusted search path vulnerability in Atom Electron before 0.33.5 allows local ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-1202</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-1202</guid>
    <pubDate>Mon, 25 Apr 2016 18:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-1202</strong></p>
  <p>Untrusted search path vulnerability in Atom Electron before 0.33.5 allows local users to gain privileges via a Trojan horse Node.js module in a parent directory of a directory named on a require line.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-1202">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-4735 – The Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electron...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4735</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4735</guid>
    <pubDate>Sun, 30 Jun 2013 19:28:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-4735</strong></p>
  <p>The Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 have a default password for an administrative account, which makes it easier for remote attackers to obtain access via an IP network.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4735">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-5090 – Electron Inc. Advanced Electron Forum before 1.0.7 allows remote attackers to ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-5090</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-5090</guid>
    <pubDate>Fri, 14 Nov 2008 19:20:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-5090</strong></p>
  <p>Electron Inc. Advanced Electron Forum before 1.0.7 allows remote attackers to execute arbitrary PHP code via PHP code embedded in bbcode in the email parameter, which is processed by the preg_replace function with the eval switch.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-5090">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
