PT-2026-54019 · Npm · Electron-Updater

·

CVE-2026-54673

·

Published

2026-06-30

·

Updated

2026-07-24

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions electron-updater versions prior to 9.7.0
Description The HTTP redirect handler HttpExecutor.prepareRedirectUrlOptions() only removes credential headers that exactly match the lowercase string "authorization". Consequently, other credential-bearing headers, such as PRIVATE-TOKEN or mixed-case Authorization headers, are not stripped and may be forwarded to an attacker-controlled cross-origin redirect destination, leading to credential exposure.
Recommendations Update to version 9.7.0.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54673
GHSA-P2F4-R6V6-J797
OPENSUSE-SU-2026:11200-1

Affected Products

Electron-Updater