CVE-2024-29900

    Dashboard / Vulnerabilities / CVE-2024-29900

    CVE-2024-29900

    Published: 29 Mar 2024Last Modified: 12 Aug 2026

    Summary: @electron/packager's build process memory potentially leaked into final executable

    Details: Electron Packager bundles Electron-based application source code with a renamed Electron executable and supporting files into folders ready for distribution. A random segment of ~1-10kb of Node.js heap memory allocated either side of a known buffer will be leaked into the final executable. This memory _could_ contain sensitive information such as environment variables, secrets files, etc. This issue is patched in 18.3.1.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 224cc6a28ddfcf4d1a184a25d10833cf153e3bda

    Affected versions

    18.3.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2024-29900 | CVE-DB