High severity7.5NVD Advisory· Published Mar 29, 2024· Updated Jun 17, 2026
CVE-2024-29900
CVE-2024-29900
Description
Electron Packager bundles Electron-based application source code with a renamed Electron executable and supporting files into folders ready for distribution. A random segment of ~1-10kb of Node.js heap memory allocated either side of a known buffer will be leaked into the final executable. This memory _could_ contain sensitive information such as environment variables, secrets files, etc. This issue is patched in 18.3.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@electron/packagernpm | >= 18.3.0, < 18.3.1 | 18.3.1 |
Affected products
3- electron/packagerv5Range: = 18.3.0
Patches
Vulnerability mechanics
References
4- github.com/electron/packager/commit/d421d4bd3ced889a4143c5c3ab6d95e3be249eeenvdPatchWEB
- github.com/advisories/GHSA-34h3-8mw4-qw57ghsaADVISORY
- github.com/electron/packager/security/advisories/GHSA-34h3-8mw4-qw57nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-29900ghsaADVISORY
News mentions
0No linked articles in our index yet.