Vulnerabilities/

Electron vulnerable to URL spoofing via PDFium

Severity:
Medium

Description

Electron version 1.7.0 - 1.7.5 is vulnerable to a URL Spoofing problem when opening PDFs in PDFium resulting loading arbitrary PDFs that a hacker can control.

Recommendation

Update the Electron package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
Electron
Anything's wrong? Let us know Last updated on September 13, 2023