Exposure of Resource to Wrong Sphere in npm/electron


CVE-2021-39184, GHSA-mpjm-v997-c4h4

Package Slug



Exposure of Resource to Wrong Sphere


Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability allows a sandboxed renderer to request a thumbnail image of an arbitrary file on the user's system. The thumbnail can potentially include significant parts of the original file, including textual data in many cases. all contain a fix for the vulnerability. Two workarounds aside from upgrading are available. One may make the vulnerability significantly more difficult for an attacker to exploit by enabling contextIsolation in one's app. One may also disable the functionality of the createThumbnailFromPath API if one does not need it.

Affected Versions

All versions starting from 10.1.0 before 11.5.0, all versions starting from 12.0.0 before 12.1.0, all versions starting from 13.0.0 before 13.3.0, all versions starting from 14.0.0 up to 15.0.0


Upgrade to versions 11.5.0, 12.1.0, 13.3.0, 15.1.0 or above.

Last Modified