1"use strict";(self.webpackChunkelectronjs=self.webpackChunkelectronjs||[]).push([["20017"],{43953(e,t,s){s.r(t),s.d(t,{assets:()=>c,contentTitle:()=>o,default:()=>d,frontMatter:()=>i,metadata:()=>a,toc:()=>l});var a=s(92340),r=s(74848),n=s(28453);let i={title:'Statement regarding "runAsNode" CVEs',date:new Date("2024-02-07T12:00:00.000Z"),authors:["VerteDinde","felixrieseberg"],slug:"statement-run-as-node-cves",tags:["security"]},o,c={authorsImageUrls:[void 0,void 0]},l=[{value:"How might this impact me?",id:"how-might-this-impact-me",level:3},{value:"Am I impacted?",id:"am-i-impacted",level:3},{value:"Mitigation",id:"mitigation",level:3}];function h(e){let t={a:"a",blockquote:"blockquote",code:"code",em:"em",h3:"h3",p:"p",...(0,n.R)(),...e.components};return(0,r.jsxs)(r.Fragment,{children:[(0,r.jsxs)(t.p,{children:["Earlier today, the Electron team was alerted to several public CVEs recently filed against several notable Electron apps. The CVEs are related to two of Electron\u2019s ",(0,r.jsx)(t.a,{href:"https://www.electronjs.org/docs/latest/tutorial/fuses",children:"fuses"})," - ",(0,r.jsx)(t.code,{children:"runAsNode"})," and ",(0,r.jsx)(t.code,{children:"enableNodeCliInspectArguments"})," - and incorrectly claim that a remote attacker is able to execute arbitrary code via these components if they have not been actively disabled."]}),"\n",(0,r.jsxs)(t.p,{children:["We do not believe that these CVEs were filed in good faith. First of all, the statement is incorrect - the configuration does ",(0,r.jsx)(t.em,{children:"not"})," enable remote code execution. Secondly, companies called out in these CVEs have not been notified despite having bug bounty programs. Lastly, while we do believe that disabling the components in question enhances app security, we do not believe that the CVEs have been filed with the correct severity. \u201CCritical\u201D is reserved for issues of the highest danger, which is certainly not the case here."]}),"\n",(0,r.jsx)(t.p,{children:"Anyone is able to request a CVE. While this is good for the overall health of the software industry, \u201Cfarming CVEs\u201D to bolster the reputation of a single security researcher is not helpful."}),"\n",(0,r.jsxs)(t.p,{children:["That said, we understand that the mere existence of a CVE with the scary ",(0,r.jsx)(t.code,{children:"critical"})," severity might lead to end user confusion, so as a project, we\u2019d like to offer guidance and assistance in dealing with the issue."]}),"\n",(0,r.jsx)(t.h3,{id:"how-might-this-impact-me",children:"How might this impact me?"}),"\n",(0,r.jsx)(t.p,{children:"After reviewing the CVEs, the Electron team believes that these CVEs are not critical."}),"\n",(0,r.jsxs)(t.p,{children:["An attacker needs to already be able to execute arbitrary commands on the machine, either by having physical access to the hardware or by having achieved full remote code execution. This bears repeating: The vulnerability described ",(0,r.jsx)(t.em,{children:"requires an attacker to already have access to the attacked system"}),"."]}),"\n",(0,r.jsxs)(t.p,{children:["Chrome, for example, ",(0,r.jsx)(t.a,{href:"https://chromium.googlesource.com/chromium/src/+/master/docs/security/faq.md#Why-arent-physically_local-attacks-in-Chromes-threat-model",children:"does not consider physically-local attacks in their threat model"}),":"]}),"\n",(0,r.jsxs)(t.blockquote,{children:["\n",(0,r.jsxs)(t.p,{children:["We consider these attacks outside Chrome's threat model, because there is no way for Chrome (or any application) to defend against a malicious user who has managed to log into your device as you, or who can run software with the privileges of your operating system user account. Such an attacker can modify executables and DLLs, change environment variables like\xa0",(0,r.jsx)(t.code,{children:"PATH"}),", change configuration files, read any data your user account owns, email it to themselves, and so on. Such an attacker has total control over your device, and nothing Chrome can do would provide a serious guarantee of defense. This problem is not special to Chrome \xad\u2014 all applications must trust the physically-local user."]}),"\n"]}
1),"\n",(0,r.jsxs)(t.p,{children:["The exploit described in the CVEs allows an attacker to then use the impacted app as a generic Node.js process with inherited TCC permissions. So if the app, for example, has been granted access to the address book, the attacker can run the app as Node.js and execute arbitrary code which will inherit that address book access. This is commonly known as a \u201C",(0,r.jsx)(t.a,{href:"https://www.crowdstrike.com/cybersecurity-101/living-off-the-land-attacks-lotl/",children:"living off the land"}),"\u201D attack. Attackers usually use PowerShell, Bash, or similar tools to run arbitrary code."]}),"\n",(0,r.jsx)(t.h3,{id:"am-i-impacted",children:"Am I impacted?"}),"\n",(0,r.jsxs)(t.p,{children:["By default, all released versions of Electron have the ",(0,r.jsx)(t.code,{children:"runAsNode"})," and ",(0,r.jsx)(t.code,{children:"enableNodeCliInspectArguments"})," features enabled. If you have not turned them off as described in the ",(0,r.jsx)(t.a,{href:"https://www.electronjs.org/docs/latest/tutorial/fuses",children:"Electron Fuses documentation"}),", your app is equally vulnerable to being used as a \u201Cliving off the land\u201D attack. Again, we need to stress that an attacker needs to ",(0,r.jsx)(t.em,{children:"already"})," be able to execute code and programs on the victim\u2019s machine."]}),"\n",(0,r.jsx)(t.h3,{id:"mitigation",children:"Mitigation"}),"\n",(0,r.jsxs)(t.p,{children:["The easiest way to mitigate this issue is to disable the ",(0,r.jsx)(t.code,{children:"runAsNode"})," fuse within your Electron app. The ",(0,r.jsx)(t.code,{children:"runAsNode"})," fuse toggles whether the ",(0,r.jsx)(t.code,{children:"ELECTRON_RUN_AS_NODE"})," environment variable is respected or not. Please see the ",(0,r.jsx)(t.a,{href:"https://www.electronjs.org/docs/latest/tutorial/fuses",children:"Electron Fuses documentation"})," for information on how to toggle theses fuses."]}),"\n",(0,r.jsxs)(t.p,{children:["Please note that if this fuse is disabled, then ",(0,r.jsx)(t.code,{children:"process.fork"})," in the main process will not function as expected as it depends on this environment variable to function. Instead, we recommend that you use ",(0,r.jsx)(t.a,{href:"https://www.electronjs.org/docs/latest/api/utility-process",children:"Utility Processes"}),", which work for many use cases where you need a standalone Node.js process (like a Sqlite server process or similar scenarios)."]}),"\n",(0,r.jsxs)(t.p,{children:["You can find more info about security best practices we recommend for Electron apps in our ",(0,r.jsx)(t.a,{href:"https://www.electronjs.org/docs/latest/tutorial/security",children:"Security Checklist"}),"."]})]})}function d(e={}){let{wrapper:t}={...(0,n.R)(),...e.components};return t?(0,r.jsx)(t,{...e,children:(0,r.jsx)(h,{...e})}):h(e)}},28453(e,t,s){s.d(t,{R:()=>i,x:()=>o});var a=s(96540);let r={},n=a.createContext(r);function i(e){let t=a.useContext(n);return a.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function o(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(r):e.components||r:i(e.components),a.createElement(n.Provider,{value:t},e.children)}},92340(e){e.exports=JSON.parse('{"permalink":"/blog/statement-run-as-node-cves","source":"@site/blog/run-as-node-cves.md","title":"Statement regarding \\"runAsNode\\" CVEs","description":"Earlier today, the Electron team was alerted to several public CVEs recently filed against several notable Electron apps. The CVEs are related to two of Electron\u2019s fuses - runAsNode and enableNodeCliInspectArguments - and incorrectly claim that a remote attacker is able to execute arbitrary code via these components if they have not been actively disabled.","date":"2024-02-07T12:00:00.000Z","tags":[{"inline":false,"label":"Security","permalink":"/blog/tags/security","description":"Blog posts related to security"}],"readingTime":3.65,"hasTruncateMarker":false,"authors":[{"name":"VerteDinde","url":"https://github.com/VerteDinde","imageURL":"https://github.com/VerteDinde.png?size=96","key":"VerteDinde","page":null},{"name":"felixrieseberg","url":"https://github.com/felixrieseberg","imageURL":"https://github.com/felixrieseberg.png?size=96","key":"feli
1xrieseberg","page":null}],"frontMatter":{"title":"Statement regarding \\"runAsNode\\" CVEs","date":"2024-02-07T12:00:00.000Z","authors":["VerteDinde","felixrieseberg"],"slug":"statement-run-as-node-cves","tags":["security"]},"unlisted":false,"prevItem":{"title":"Introducing electron/rfcs","permalink":"/blog/rfcs"},"nextItem":{"title":"Electron 28.0.0","permalink":"/blog/electron-28-0"}}')}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.