Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-54673— electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`

Quick assessment

Affected
electron-userland electron-builder
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Electron Userland electron-builder是Electron Userland组织的一款构建跨平台桌面应用的开发工具。 Electron Userland electron-builder存在信息泄露漏洞,该漏洞源于HTTP重定向处理函数只剥离了全小写“authorization”凭据标头,导致其他凭据标头(如PRIVATE-TOKEN和混合大小写的Authorization)未被剥离,可能被转发至攻击者控制的跨域重定向目标,从而泄露凭据。

AI Predicted 7.5 Difficulty: Easy EPSS 0.41% · P33

Possible ATT&CK Techniques 1 AI

T1071 · Application Layer Protocol

Affected Version Matrix 2

VendorProduct Version RangeStatus
electron-userland builder-util-runtime < 9.7.0 affected
electron-userland electron-builder < 26.15.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54673

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`
Source: CVE Program / CVE List V5
Vulnerability Description
electron-updater allows for automatic updates for Electron apps. Prior to 9.7.0, the HTTP redirect handler (HttpExecutor.prepareRedirectUrlOptions) only stripped a credential header whose key string matched exactly lowercase "authorization", exposing credentials. Other credential-bearing headers — most notably PRIVATE-TOKEN (used by GitLab's personal access token flow) and mixed-case Authorization (used by GitLab's Bearer/OAuth flow) — were not stripped and could be forwarded to an attacker-controlled cross-origin redirect destination. This issue has been fixed in version 9.7.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5
Vulnerability Title
Electron Userland electron-builder 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Electron Userland electron-builder是Electron Userland组织的一款构建跨平台桌面应用的开发工具。 Electron Userland electron-builder存在信息泄露漏洞,该漏洞源于HTTP重定向处理函数只剥离了全小写“authorization”凭据标头,导致其他凭据标头(如PRIVATE-TOKEN和混合大小写的Authorization)未被剥离,可能被转发至攻击者控制的跨域重定向目标,从而泄露凭据。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
electron-userland electron-builder < 26.15.0 -
electron-userland builder-util-runtime < 9.7.0 -

II. Public POCs for CVE-2026-54673

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54673

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-54673 (1)

Vendor Advisories for CVE-2026-54673 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-54673

No comments yet


Leave a comment