| Summary | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on macOS, app.moveToApplicationsFolder() used an AppleScript fallback path that did not properly handle certain characters in the application bundle path. Under specific conditions, a crafted launch path could lead to arbitrary AppleScript execution when the user accepted the move-to-Applications prompt. Apps are only affected if they call app.moveToApplicationsFolder(). Apps that do not use this API are not affected. This issue has been patched in versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8. |
|---|---|
| Publication Date | April 4, 2026, 9:16 a.m. |
| Registration Date | April 15, 2026, 11:25 a.m. |
| Last Update | April 15, 2026, 3:55 a.m. |
| CVSS3.1 : HIGH | |
| スコア | 7.8 |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 攻撃元区分(AV) | ローカル |
| 攻撃条件の複雑さ(AC) | 低 |
| 攻撃に必要な特権レベル(PR) | 不要 |
| 利用者の関与(UI) | 要 |
| 影響の想定範囲(S) | 変更なし |
| 機密性への影響(C) | 高 |
| 完全性への影響(I) | 高 |
| 可用性への影響(A) | 高 |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:* | 38.8.6 | ||||
| cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:* | 39.0.0 | 39.8.1 | |||
| cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:* | 40.0.0 | 40.8.0 | |||
| cpe:2.3:a:electronjs:electron:41.0.0:alpha1:*:*:*:node.js:*:* | |||||
| cpe:2.3:a:electronjs:electron:41.0.0:alpha2:*:*:*:node.js:*:* | |||||
| cpe:2.3:a:electronjs:electron:41.0.0:alpha3:*:*:*:node.js:*:* | |||||
| cpe:2.3:a:electronjs:electron:41.0.0:alpha4:*:*:*:node.js:*:* | |||||
| cpe:2.3:a:electronjs:electron:41.0.0:alpha5:*:*:*:node.js:*:* | |||||
| cpe:2.3:a:electronjs:electron:41.0.0:alpha6:*:*:*:node.js:*:* | |||||
| cpe:2.3:a:electronjs:electron:41.0.0:beta1:*:*:*:node.js:*:* | |||||
| cpe:2.3:a:electronjs:electron:41.0.0:beta2:*:*:*:node.js:*:* | |||||
| cpe:2.3:a:electronjs:electron:41.0.0:beta3:*:*:*:node.js:*:* | |||||
| cpe:2.3:a:electronjs:electron:41.0.0:beta4:*:*:*:node.js:*:* | |||||
| cpe:2.3:a:electronjs:electron:41.0.0:beta5:*:*:*:node.js:*:* | |||||
| cpe:2.3:a:electronjs:electron:41.0.0:beta6:*:*:*:node.js:*:* | |||||
| cpe:2.3:a:electronjs:electron:41.0.0:beta7:*:*:*:node.js:*:* | |||||