CVE-2024-29900
Electron Packager bundles Electron-based application source code with a renamed Electron executable and supporting files into folders ready for distribution. A random segment of ~1-10kb of Node.js heap memory allocated either side of a known buffer will be leaked into the final executable. This memory _could_ contain sensitive information such as environment variables, secrets files, etc. This issue is patched in 18.3.1.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.63%
- CWE
- CWE-402
- Published
- 2024-03-29
- Last modified
- 2026-03-13
Affected products
- electron packager
Weakness type
Related vulnerabilities
- CVE-2025-67745 — Myhoard logs backup encryption key in plain text
- CVE-2025-66422 — Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup)...
- CVE-2025-55014 — The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and...
- CVE-2025-49618 — In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId,...
- CVE-2025-52925 — In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken...
- CVE-2025-48383 — Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking
- CVE-2025-32360 — In Zammad 6.4.x before 6.4.2, there is information exposure. Only agents should be able to see and...
- CVE-2025-29925 — XWiki allows unregistered users to access private pages information through REST endpoint