CVE-2025-55305

Description

A vulnerability has been identified in Electron where ASAR integrity validation can be bypassed through modification of application resources. An attacker with local write access to the application’s installation directory can tamper with files inside the resources folder, undermining the intended protections and allowing unauthorized changes to the application.

Statement

This vulnerability is rated Moderate as it requires specific conditions for exploitation: the application must have the embeddedAsarIntegrityValidation and onlyLoadAppFromAsar fuses enabled, and the attacker must already have local write access to the application’s installation directory.

Mitigation

No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score6.1N/AN/A
Attack VectorLocalN/AN/A
Attack ComplexityLowN/AN/A
Privileges RequiredLowN/AN/A
User InteractionRequiredN/AN/A
ScopeUnchangedN/AN/A
ConfidentialityLowN/AN/A
Integrity ImpactHighN/AN/A
Availability ImpactLowN/AN/A

Vector

Red Hat: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:L

Understanding the Weakness (CWE)

Integrity,Availability,Confidentiality,Other

Technical Impact: Execute Unauthorized Code or Commands; Alter Execution Logic; Other

Executing untrusted code could compromise the control flow of the program. The untrusted code could execute attacker-controlled commands, read or modify sensitive resources, or prevent the software from functioning correctly for legitimate users.

Frequently Asked Questions

Want to get errata notifications? Sign up here.