MetaMask / MetaMask/metamask-extension

Yarn Audit: new or newly blocking advisories on main (325c118d6f)

Open
#45,247 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
13.2k
Forks
5.6k
Avg merge
2d 5h
Merged PRs (30d)
451

Description

**9** new or newly blocking advisories detected on push to `main` (0 release-blocking).

CI run: https://github.com/MetaMask/metamask-extension/actions/runs/31026449337

## Informational (dev-only or low severity)

- **electron** (high, dev-only) — Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
https://github.com/advisories/GHSA-v3j7-r9gq-3gjw
- **electron** (moderate, dev-only) — Electron: Extension tab APIs operate across session boundaries
https://github.com/advisories/GHSA-m55f-7gqj-fr98
- **electron** (moderate, dev-only) — Electron: shell.openPath path validation bypass via embedded null byte
https://github.com/advisories/GHSA-5c9j-mhmv-5xgx
- **electron** (high, dev-only) — Electron: Context isolation bypass via Function.prototype.bind hijack
https://github.com/advisories/GHSA-h7rp-cf8h-j98x
- **electron** (low, dev-only) — Electron: Cross-origin iframe can position native autofill popup
https://github.com/advisories/GHSA-x8rc-wpg4-grpf
- **electron** (moderate, dev-only) — Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
https://github.com/advisories/GHSA-9pf5-hg6p-4pwp
- **electron** (low, dev-only) — Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
https://github.com/advisories/GHSA-pfmc-3mgc-p6fp
- **electron** (moderate, dev-only) — Electron: HTTP redirect followed into local file loader
https://github.com/advisories/GHSA-v64r-4m7r-3mvq
- **electron** (moderate, dev-only) — Electron: window.open features string controls some window options considered privileged
https://github.com/advisories/GHSA-v93f-fgjr-hjrj

Native audit tree

```
├─ electron
│ ├─ ID: 1136552
│ ├─ Issue: Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
│ ├─ URL: https://github.com/advisories/GHSA-v3j7-r9gq-3gjw
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <39.8.10
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1136559
│ ├─ Issue: Electron: Extension tab APIs operate across session boundaries
│ ├─ URL: https://github.com/advisories/GHSA-m55f-7gqj-fr98
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <39.8.8
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1136560
│ ├─ Issue: Electron: shell.openPath path validation bypass via embedded null byte
│ ├─ URL: https://github.com/advisories/GHSA-5c9j-mhmv-5xgx
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <39.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1136567
│ ├─ Issue: Electron: Context isolation bypass via Function.prototype.bind hijack
│ ├─ URL: https://github.com/advisories/GHSA-h7rp-cf8h-j98x
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <39.8.9
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1136571
│ ├─ Issue: Electron: Cross-origin iframe can position native autofill popup
│ ├─ URL: https://github.com/advisories/GHSA-x8rc-wpg4-grpf
│ ├─ Severity: low
│ ├─ Vulnerable Versions: <39.8.8
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1136575
│ ├─ Issue: Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
│ ├─ URL: https://github.com/advisories/GHSA-9pf5-hg6p-4pwp
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <39.8.7
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1136579
│ ├─ Issue: Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
│ ├─ URL: https://github.com/advisories/GHSA-pfmc-3mgc-p6fp
│ ├─ Severity: low
│ ├─ Vulnerable Versions: <39.8.10
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1136590
│ ├─ Issue: Electron: HTTP redirect followed into local file loader
│ ├─ URL: https://github.com/advisories/GHSA-v64r-4m7r-3mvq
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <39.8.8
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

├─ electron
│ ├─ ID: 1136597
│ ├─ Issue: Electron: window.open features string controls some window options considered privileged
│ ├─ URL: https://github.com/advisories/GHSA-v93f-fgjr-hjrj
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <39.8.8
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5

```

Contributor guide

Open the contributing guide

Research direction

No source file or test is named. Start with the linked CI run and Native audit tree, then identify the Electron dependency entry and the project's policy for dev-only advisories. Done should be defined as addressing the advisories or documenting why they require no change.

Written by the indexing model from the issue text.

Assessment

Tech stack
electron, typescript
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.