Browse all 4 CVE security advisories affecting electron-userland. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-54672 | electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib` — electron-builder CWE-427 | 7.8 | High | 2026-06-30 |
| CVE-2026-54673 | electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime` — electron-builder CWE-200 | - | - | 2026-06-30 |
| CVE-2024-39698 | Code Signing Bypass on Windows in electron-updater < 6.3.0-alpha.6 — electron-builder CWE-154 | 7.5 | High | 2024-07-09 |
| CVE-2024-27303 | electron-builder's NSIS installer - execute arbitrary code on the target machine (Windows only) — electron-builder CWE-426 | 7.3 | High | 2024-03-06 |
This page lists every published CVE security advisory associated with electron-userland. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.