Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions below 35.7.5, 36.0.0-alpha.1 through 36.8.0, 37.0.0-alpha.1 through 37.3.1 and 38.0.0-alpha.1 through 38.0.0-beta.6, ASAR Integrity Bypass via resource modification. This only impacts apps that have the embeddedAsarIntegrityValidation and onlyLoadAppFromAsar fuses enabled. Apps without these fuses enabled are not impacted. This issue is fixed in versions 35.7.5, 36.8.1, 37.3.1 and 38.0.0-beta.6.
Metrics
Affected Vendors & Products
References
History
Fri, 05 Sep 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 05 Sep 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Electron
Electron electron |
|
Vendors & Products |
Electron
Electron electron |
Thu, 04 Sep 2025 23:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions below 35.7.5, 36.0.0-alpha.1 through 36.8.0, 37.0.0-alpha.1 through 37.3.1 and 38.0.0-alpha.1 through 38.0.0-beta.6, ASAR Integrity Bypass via resource modification. This only impacts apps that have the embeddedAsarIntegrityValidation and onlyLoadAppFromAsar fuses enabled. Apps without these fuses enabled are not impacted. This issue is fixed in versions 35.7.5, 36.8.1, 37.3.1 and 38.0.0-beta.6. | |
Title | Electron is vulnerable to Code Injection via resource modification | |
Weaknesses | CWE-829 CWE-94 |
|
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-05T15:44:54.628Z
Reserved: 2025-08-12T16:15:30.239Z
Link: CVE-2025-55305

Updated: 2025-09-05T15:44:49.863Z

Status : Awaiting Analysis
Published: 2025-09-04T23:15:33.520
Modified: 2025-09-05T17:47:10.303
Link: CVE-2025-55305

No data.

Updated: 2025-09-05T14:01:49Z