CVE-2021-39184

Summary

CVECVE-2021-39184
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2021-10-12 19:15:00 UTC
Updated2022-08-05 10:49:00 UTC
DescriptionElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to 11.5.0, 12.1.0, and 13.3.0 allows a sandboxed renderer to request a "thumbnail" image of an arbitrary file on the user's system. The thumbnail can potentially include significant parts of the original file, including textual data in many cases. Versions 15.0.0-alpha.10, 14.0.0, 13.3.0, 12.1.0, and 11.5.0 all contain a fix for the vulnerability. Two workarounds aside from upgrading are available. One may make the vulnerability significantly more difficult for an attacker to exploit by enabling `contextIsolation` in one's app. One may also disable the functionality of the `createThumbnailFromPath` API if one does not need it.

Risk And Classification

Problem Types: CWE-862

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Application Electronjs Electron All All All All
Application Electronjs Electron 14.0.0 beta1 All All
Application Electronjs Electron 14.0.0 beta10 All All
Application Electronjs Electron 14.0.0 beta11 All All
Application Electronjs Electron 14.0.0 beta12 All All
Application Electronjs Electron 14.0.0 beta13 All All
Application Electronjs Electron 14.0.0 beta14 All All
Application Electronjs Electron 14.0.0 beta15 All All
Application Electronjs Electron 14.0.0 beta16 All All
Application Electronjs Electron 14.0.0 beta17 All All
Application Electronjs Electron 14.0.0 beta18 All All
Application Electronjs Electron 14.0.0 beta19 All All
Application Electronjs Electron 14.0.0 beta2 All All
Application Electronjs Electron 14.0.0 beta20 All All
Application Electronjs Electron 14.0.0 beta21 All All
Application Electronjs Electron 14.0.0 beta22 All All
Application Electronjs Electron 14.0.0 beta23 All All
Application Electronjs Electron 14.0.0 beta24 All All
Application Electronjs Electron 14.0.0 beta25 All All
Application Electronjs Electron 14.0.0 beta3 All All
Application Electronjs Electron 14.0.0 beta4 All All
Application Electronjs Electron 14.0.0 beta5 All All
Application Electronjs Electron 14.0.0 beta6 All All
Application Electronjs Electron 14.0.0 beta7 All All
Application Electronjs Electron 14.0.0 beta8 All All
Application Electronjs Electron 14.0.0 beta9 All All
Application Electronjs Electron 15.0.0 alpha1 All All
Application Electronjs Electron 15.0.0 alpha2 All All
Application Electronjs Electron 15.0.0 alpha3 All All
Application Electronjs Electron 15.0.0 alpha4 All All
Application Electronjs Electron 15.0.0 alpha5 All All
Application Electronjs Electron 15.0.0 alpha6 All All
Application Electronjs Electron 15.0.0 alpha7 All All
Application Electronjs Electron 15.0.0 alpha8 All All
Application Electronjs Electron 15.0.0 alpha9 All All

References

ReferenceSourceLinkTags
fix: remove ipc wrapper for nativeImage.createThumbnailFromPath by nornagon · Pull Request #30728 · electron/electron · GitHub MISC github.com
Sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage API · Advisory · electron/electron · GitHub CONFIRM github.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Legacy QID Mappings

  • 980372 Nodejs (npm) Security Update for electron (GHSA-mpjm-v997-c4h4)

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report