NW.js is a framework for building desktop applications by combining Chromium and Node.js, presenting a narrow but strategically positioned product surface where application developers embed the runtime to bridge web and native capabilities. Its observed vulnerabilities cluster around input validation, encryption practices, and information disclosure patterns that reflect the challenge of securing the boundary between web-hosted code and system resources. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nwjs over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-9530CRITICAL A vulnerability exists in nw.js before 0.11.3 when calling nw methods from normal frames, which has an unspecified impact. | Feb 7, 2020 | 9.8 | 27 | NO | NO |
CVE-2014-9733CRITICAL nw.js before 0.11.5 can simulate user input events in a normal frame, which allows remote attackers to have unspecified impact via unknown vectors. | Oct 17, 2017 | 9.8 | 24 | NO | NO |
CVE-2016-10588HIGH nw is an installer for nw.js. nw downloads zipped resources over HTTP, It may be possible to cause remote code execution (RCE) by swapping out the requested zip file with an attack | Jun 1, 2018 | 8.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nwjs.
Media articles that mention a CVE ID that affects a product developed by Nwjs — matched by CVE ID, not by vendor name.