# CVE-2024-29900

## Summary

- **CVE ID:** CVE-2024-29900
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-402
- **Published:** Mar 29, 2024
- **Last Modified:** Mar 13, 2026

## Description

Electron Packager bundles Electron-based application source code with a renamed Electron executable and supporting files into folders ready for distribution. A random segment of ~1-10kb of Node.js heap memory allocated either side of a known buffer will be leaked into the final executable. This memory _could_ contain sensitive information such as environment variables, secrets files, etc. This issue is patched in 18.3.1.

## Affected Products

- electron — packager (= 18.3.0)

## References

- [CNA](https://github.com/electron/packager/security/advisories/GHSA-34h3-8mw4-qw57)
- [CNA](https://github.com/electron/packager/commit/d421d4bd3ced889a4143c5c3ab6d95e3be249eee)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.63%
- **EPSS Percentile:** 48.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-12._