Atom's vulnerability footprint is concentrated in a small set of products centered on the Electron framework and related tooling, reflecting exposure points in desktop application and framework components. The observed weakness classes include OS command injection and various input-handling issues characteristic of application-layer attack surfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Atom over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000006HIGH GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically Electron apps running on Windows | Jan 24, 2018 | 8.8 | 88 | NO | YES |
CVE-2007-3134MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in atomPhotoBlog.php in Atom PhotoBlog 1.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the ( | Jun 8, 2007 | 4.3 | 22 | NO | YES |
CVE-2016-1202HIGH Untrusted search path vulnerability in Atom Electron before 0.33.5 allows local users to gain privileges via a Trojan horse Node.js module in a parent directory of a directory name | Apr 25, 2016 | 7.8 | 20 | NO | NO |
CVE-2017-1000424MEDIUM Github Electron version 1.6.4 - 1.6.11 and 1.7.0 - 1.7.5 is vulnerable to a URL Spoofing problem when opening PDFs in PDFium resulting loading arbitrary PDFs that a hacker can cont | Jan 2, 2018 | 4.3 | 18 | NO | NO |
CVE-2020-35897MEDIUM An issue was discovered in the atom crate before 0.3.6 for Rust. An unsafe Send implementation allows a cross-thread data race. | Dec 31, 2020 | 4.7 | 17 | NO | NO |
CVE-2007-3135MEDIUM Cross-site scripting (XSS) vulnerability in atomPhotoBlog.php in Atom Photoblog 1.0.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the tag paramet | Jun 8, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Atom.
Media articles that mention a CVE ID that affects a product developed by Atom — matched by CVE ID, not by vendor name.