CVE-2025-55305

Source
https://cve.org/CVERecord?id=CVE-2025-55305
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-55305.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-55305
Aliases
Published
2025-09-04T23:05:07.274Z
Modified
2026-08-12T15:16:44.986290Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:L CVSS Calculator
Summary
Electron is vulnerable to Code Injection via resource modification
Details

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions below 35.7.5, 36.0.0-alpha.1 through 36.8.0, 37.0.0-alpha.1 through 37.3.1 and 38.0.0-alpha.1 through 38.0.0-beta.6, ASAR Integrity Bypass via resource modification. This only impacts apps that have the embeddedAsarIntegrityValidation and onlyLoadAppFromAsar fuses enabled. Apps without these fuses enabled are not impacted. This issue is fixed in versions 35.7.5, 36.8.1, 37.3.1 and 38.0.0-beta.6.

Database specific
{
    "cwe_ids": [
        "CWE-829",
        "CWE-94"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/55xxx/CVE-2025-55305.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/electron/electron

Affected ranges

Type
GIT
Repo
https://github.com/electron/electron
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "36.0.0-alpha.1"
        },
        {
            "fixed": "36.8.0"
        },
        {
            "introduced": "37.0.0-alpha.1"
        },
        {
            "fixed": "37.3.1"
        },
        {
            "introduced": "38.0.0-alpha.1"
        },
        {
            "fixed": "38.0.0-beta.6"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

v36.*
v36.0.0
v36.0.0-alpha.1
v36.0.0-alpha.2
v36.0.0-alpha.3
v36.0.0-alpha.4
v36.0.0-alpha.5
v36.0.0-alpha.6
v36.0.0-beta.1
v36.0.0-beta.2
v36.0.0-beta.3
v36.0.0-beta.4
v36.0.0-beta.5
v36.0.0-beta.6
v36.0.0-beta.7
v36.0.0-beta.8
v36.0.0-beta.9
v36.0.1
v36.1.0
v36.2.0
v36.2.1
v36.3.0
v36.3.1
v36.3.2
v36.4.0
v36.5.0
v36.6.0
v36.7.0
v36.7.1
v36.7.2
v36.7.3
v36.7.4
v36.8.0
v37.*
v37.0.0
v37.0.0-alpha.1
v37.0.0-alpha.2
v37.0.0-alpha.3
v37.0.0-alpha.4
v37.0.0-alpha.5
v37.0.0-alpha.6
v37.0.0-alpha.7
v37.0.0-beta.1
v37.0.0-beta.2
v37.0.0-beta.3
v37.0.0-beta.4
v37.0.0-beta.5
v37.0.0-beta.6
v37.0.0-beta.7
v37.0.0-beta.8
v37.0.0-beta.9
v37.1.0
v37.2.0
v37.2.1
v37.2.2
v37.2.3
v37.2.4
v37.2.5
v37.2.6
v37.3.0
v38.*
v38.0.0-alpha.1
v38.0.0-alpha.10
v38.0.0-alpha.11
v38.0.0-alpha.12
v38.0.0-alpha.13
v38.0.0-alpha.2
v38.0.0-alpha.3
v38.0.0-alpha.4
v38.0.0-alpha.5
v38.0.0-alpha.6
v38.0.0-alpha.7
v38.0.0-alpha.8
v38.0.0-alpha.9
v38.0.0-beta.1
v38.0.0-beta.2
v38.0.0-beta.3
v38.0.0-beta.4
v38.0.0-beta.5
v39.*
v39.0.0-nightly.20250625
v39.0.0-nightly.20250701
v39.0.0-nightly.20250702
v39.0.0-nightly.20250703
v39.0.0-nightly.20250704
v39.0.0-nightly.20250708
v39.0.0-nightly.20250709
v39.0.0-nightly.20250711
v39.0.0-nightly.20250714
v39.0.0-nightly.20250715
v39.0.0-nightly.20250716
v39.0.0-nightly.20250717
v39.0.0-nightly.20250718
v39.0.0-nightly.20250721
v39.0.0-nightly.20250722
v39.0.0-nightly.20250723
v39.0.0-nightly.20250724
v39.0.0-nightly.20250725
v39.0.0-nightly.20250728
v39.0.0-nightly.20250729
v39.0.0-nightly.20250731
v39.0.0-nightly.20250801
v39.0.0-nightly.20250804
v39.0.0-nightly.20250805
v39.0.0-nightly.20250806
v39.0.0-nightly.20250807
v39.0.0-nightly.20250808
v39.0.0-nightly.20250811
v39.0.0-nightly.20250814
v39.0.0-nightly.20250815
v39.0.0-nightly.20250817
v39.0.0-nightly.20250818

Database specific

vanir_signatures_modified
"2026-08-12T15:16:44Z"
vanir_signatures
[
    {
        "id": "CVE-2025-55305-336a40a1",
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "152494666416781242810517719231320519604",
                "225621294261284233076206802270263648551",
                "115705440781529763113046962627444993970",
                "178111412695478762709679865612109648560",
                "73911844454750564959446202323068893232",
                "64816077172179537187033353531511817411",
                "190079685644089414390125721502882456053",
                "164275026456403570511986551124445333960",
                "68083282541239337707222991128337435119",
                "114137547968448916044453027153094341473",
                "118177717049838624043161370458456721742",
                "87335272485147941561134939866151684502",
                "38125503356101783604380867880620683274",
                "69703252615889611887930220466027851786",
                "185625927738076278198987677630051462644",
                "56534108699571538400922224531377193095",
                "137426709248835087988570973629493043965",
                "58389083308274755672287779275857279236",
                "171193114796557878735715665164735886437",
                "51419638149645591552157167443980661617",
                "227302053439300061261615587786720510760",
                "45601092781832770462638305846789432113",
                "7510572762033959665471238074058011916",
                "228184583599411597763315124517698770354"
            ]
        },
        "source": "https://github.com/electron/electron/commit/23a02934510fcf951428e14573d9b2d2a3c4f28b",
        "target": {
            "file": "shell/app/electron_main_delegate.cc"
        }
    },
    {
        "id": "CVE-2025-55305-7a090bbf",
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "152494666416781242810517719231320519604",
                "225621294261284233076206802270263648551",
                "115705440781529763113046962627444993970",
                "178111412695478762709679865612109648560",
                "73911844454750564959446202323068893232",
                "64816077172179537187033353531511817411",
                "190079685644089414390125721502882456053",
                "164275026456403570511986551124445333960",
                "68083282541239337707222991128337435119",
                "114137547968448916044453027153094341473",
                "39518479210953554078288018750913182872",
                "242982796452390228803972713655085831361",
                "93936354092902648516486098748147714529",
                "69703252615889611887930220466027851786",
                "185625927738076278198987677630051462644",
                "56534108699571538400922224531377193095",
                "137426709248835087988570973629493043965",
                "58389083308274755672287779275857279236",
                "171193114796557878735715665164735886437",
                "51419638149645591552157167443980661617",
                "227302053439300061261615587786720510760",
                "45601092781832770462638305846789432113",
                "7510572762033959665471238074058011916",
                "228184583599411597763315124517698770354"
            ]
        },
        "source": "https://github.com/electron/electron/commit/fdf29ce83870109d403f5c23ae529dbd0e8f4fee",
        "target": {
            "file": "shell/app/electron_main_delegate.cc"
        }
    },
    {
        "id": "CVE-2025-55305-b8eb7440",
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "64816077172179537187033353531511817411",
                "190079685644089414390125721502882456053",
                "164275026456403570511986551124445333960",
                "68083282541239337707222991128337435119",
                "114137547968448916044453027153094341473",
                "118177717049838624043161370458456721742",
                "87335272485147941561134939866151684502",
                "38125503356101783604380867880620683274",
                "69703252615889611887930220466027851786",
                "185625927738076278198987677630051462644",
                "56534108699571538400922224531377193095",
                "137426709248835087988570973629493043965",
                "58389083308274755672287779275857279236",
                "171193114796557878735715665164735886437",
                "51419638149645591552157167443980661617",
                "227302053439300061261615587786720510760",
                "45601092781832770462638305846789432113",
                "7510572762033959665471238074058011916",
                "228184583599411597763315124517698770354"
            ]
        },
        "source": "https://github.com/electron/electron/commit/3f92511cdecc39f46b0e86cce40a0c691e301c9d",
        "target": {
            "file": "shell/app/electron_main_delegate.cc"
        }
    },
    {
        "id": "CVE-2025-55305-ed3d31ca",
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "152494666416781242810517719231320519604",
                "225621294261284233076206802270263648551",
                "115705440781529763113046962627444993970",
                "178111412695478762709679865612109648560",
                "73911844454750564959446202323068893232",
                "64816077172179537187033353531511817411",
                "190079685644089414390125721502882456053",
                "164275026456403570511986551124445333960",
                "68083282541239337707222991128337435119",
                "114137547968448916044453027153094341473",
                "39518479210953554078288018750913182872",
                "242982796452390228803972713655085831361",
                "93936354092902648516486098748147714529",
                "69703252615889611887930220466027851786",
                "185625927738076278198987677630051462644",
                "56534108699571538400922224531377193095",
                "137426709248835087988570973629493043965",
                "58389083308274755672287779275857279236",
                "171193114796557878735715665164735886437",
                "51419638149645591552157167443980661617",
                "227302053439300061261615587786720510760",
                "45601092781832770462638305846789432113",
                "7510572762033959665471238074058011916",
                "228184583599411597763315124517698770354"
            ]
        },
        "source": "https://github.com/electron/electron/commit/2e5a0b7220ebf955c6785cc5adb2e2b1cf77dac1",
        "target": {
            "file": "shell/app/electron_main_delegate.cc"
        }
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-55305.json"