CVE-2017-16151
Last modified
CVE-2017-16151 is a vulnerability of currently unknown severity. Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects all recent versions of Electron. Any Electron app that accesses remote content is vulnerable to this exploit, regardless of whether the [sandbox option](https://electron.atom.io/docs/api/sandbox-option) is enabled.. EPSS estimates a 2.72% chance of exploitation in the next 30 days.
Description
Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects all recent versions of Electron. Any Electron app that accesses remote content is vulnerable to this exploit, regardless of whether the [sandbox option](https://electron.atom.io/docs/api/sandbox-option) is enabled.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Electronjs | Electron | < 1.7.8 |
References
- https://nodesecurity.io/advisories/539Third Party Advisory
- https://nodesecurity.io/advisories/539Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-16151?
How severe is CVE-2017-16151?
How do I fix CVE-2017-16151?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-16145sspa is a server dedicated to single-page apps. sspa is vuln…
- CVE-2017-16146mockserve is a file server. mockserve is vulnerable to a dir…
- CVE-2017-16147shit-server is a file server. shit-server is vulnerable to a…
- CVE-2017-16148serve46 is a static file server. serve46 is vulnerable to a …
- CVE-2017-16149zwserver is a weather web server. zwserver is vulnerable to …
- CVE-2017-16150wanggoujing123 is a simple webserver. wanggoujing123 is vuln…
- CVE-2017-16152static-html-server is a static file server. static-html-serv…
- CVE-2017-16153gaoxuyan is vulnerable to a directory traversal issue, givin…
- CVE-2017-16154earlybird is a web server module for early development. earl…
- CVE-2017-16155fast-http-cli is the command line interface for fast-http, a…
- CVE-2017-16156myprolyz is a static file server. myprolyz is vulnerable to …
- CVE-2017-16157censorify.tanisjr is a simple web server and API RESTful ser…
Are you affected by CVE-2017-16151?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
