MEDIUM 4.3 npm
Electron vulnerable to URL spoofing via PDFium
GHSA-6h98-cf9g-vmg2 · CVE-2017-1000424
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Electron version 1.7.0 - 1.7.5 is vulnerable to a URL Spoofing problem when opening PDFs in PDFium resulting loading arbitrary PDFs that a hacker can control.
Ready to move
Start Securing
Free, no credit card | First findings in minutes