Asana's vulnerability profile centers on its project-management and collaboration platform, with observed disclosures clustering around access-control and code-injection weaknesses affecting its desktop application. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Asana over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-49314HIGH Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode and | Nov 28, 2023 | 7.8 | 25 | NO | NO |
CVE-2022-26877MEDIUM Asana Desktop before 1.6.0 allows remote attackers to exfiltrate local files if they can trick the Asana desktop app into loading a malicious web page. | Apr 9, 2022 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Asana.
Media articles that mention a CVE ID that affects a product developed by Asana — matched by CVE ID, not by vendor name.