Vulnerabilities/

Electerm's full process.env exposed to renderer via window.pre.env

Severity:
Medium

Description

The getConstants() IPC handler in src/app/lib/ipc-sync.js serialises the entire process.env object and sends it to the renderer. The data is stored as window.pre.env and is accessible from any JavaScript running in the renderer (e.g., via the DevTools console or a compromised webview context).

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
electerm
Anything's wrong? Let us know Last updated on May 08, 2026