Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Armcord 3.2.4 still uses vulnerable Electron 26.1.0 #471

Closed
LudovicoPiero opened this issue Sep 24, 2023 · 5 comments
Closed

Armcord 3.2.4 still uses vulnerable Electron 26.1.0 #471

LudovicoPiero opened this issue Sep 24, 2023 · 5 comments
Labels
bug Something isn't working

Comments

@LudovicoPiero
Copy link

Describe the bug
Latest Release still using the vulnerable Electron 26.1.0

Additional context
For more info, check NixOS/nixpkgs#254798 (comment)

@LudovicoPiero LudovicoPiero added the bug Something isn't working label Sep 24, 2023
@smartfrigde
Copy link
Member

There's a unstable release with Electron 27 Beta 2 which appears to patch it according to change logs. I'm waiting for a stable E27 release first for it to be on a stable tag

@tazz4843
Copy link

tazz4843 commented Sep 27, 2023

I feel like stability should quite frankly be thrown out the window here. This is a dead easy exploit to use, and all it takes is a few script kiddies before someone's device is done for. I guarantee there will be script kiddies posting this all over Discord within days.

@Vendicated
Copy link
Contributor

Discord is most likely inherently not affected because all images are proxied through their media proxy which re-encodes images anyway

In any case, a bump from 26.1.0 to 26.2.1 would still be very good to fix the vulnerability, to reduce the impact of things that could potentially happen like Discord having another XSS

@Phoenix616
Copy link

Phoenix616 commented Sep 29, 2023

26.2.1 indeed updated Chromium to a fixed version so this should be a very minor update and not requiring a wait for 27. (Without this update one should not trust this application. Even though Discord might re-encode uploaded files there are a couple other places one can easily imagine where images are displayed directly and not from Discord's servers...)

@taukakao
Copy link

taukakao commented Nov 7, 2023

This is not relevant anymore.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

7 participants