CVE detail
CVE-2024-29900 — CVE-2024-29900
Published 2024-03-29 · Modified 2026-06-17 · Vendor openjsf · Product packager · Source nvd
HIGH
severity
CVSS-derived band
0.0063
EPSS probability
exploitation probability, 30d
47.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Electron Packager bundles Electron-based application source code with a renamed Electron executable and supporting files into folders ready for distribution. A random segment of ~1-10kb of Node.js heap memory allocated either side of a known buffer will be leaked into the final executable. This memory _could_ contain sensitive information such as environment variables, secrets files, etc. This issue is patched in 18.3.1.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References