Skip to content

[DevTools Bug]: react-devtools depends on vulnerable version of electron #25667

@slobo80

Description

@slobo80

Website or app

https://github.com/facebook/react/blob/main/packages/react-devtools/package.json

Repro steps

Issue

electron package versions <18.3.7 suffer from a security vulnerability: "Exfiltration of hashed SMB credentials on Windows via file:// redirect".
See GHSA-p2jh-44qj-pf2v

Solution

Upgrade electron dependency in react-devtools to >18.3.7

How often does this bug happen?

Every time

DevTools package (automated)

No response

DevTools version (automated)

No response

Error message (automated)

No response

Error call stack (automated)

No response

Error component stack (automated)

No response

GitHub query string (automated)

No response

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions