CVE-2018-15685 describes a remote code execution (RCE) vulnerability in GitHub Electron versions 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6. This high-severity flaw, rated 8.1 CVSS, allows an attacker to execute arbitrary code by exploiting specific configurations involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true" options. While not actively exploited in the wild (not in KEV), public exploit code exists on ExploitDB, and there has been some community discussion regarding this "nodeIntegration bypass bug."
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.7.15CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:1.7.15:*:*:*:*:*:*:* | ||
1.8.7CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:1.8.7:*:*:*:*:*:*:* | ||
2.0.7CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:2.0.7:*:*:*:*:*:*:* | ||
3.0.0CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:3.0.0:beta6:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.