MetaMask / MetaMask/metamask-extension
Yarn Audit: new or newly blocking advisories on main (325c118d6f)
- Dominant language
- TypeScript
- Stars
- 13.2k
- Forks
- 5.6k
- Avg merge
- 2d 5h
- Merged PRs (30d)
- 451
Description
**9** new or newly blocking advisories detected on push to `main` (0 release-blocking).
CI run: https://github.com/MetaMask/metamask-extension/actions/runs/31026449337
## Informational (dev-only or low severity)
- **electron** (high, dev-only) — Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
https://github.com/advisories/GHSA-v3j7-r9gq-3gjw
- **electron** (moderate, dev-only) — Electron: Extension tab APIs operate across session boundaries
https://github.com/advisories/GHSA-m55f-7gqj-fr98
- **electron** (moderate, dev-only) — Electron: shell.openPath path validation bypass via embedded null byte
https://github.com/advisories/GHSA-5c9j-mhmv-5xgx
- **electron** (high, dev-only) — Electron: Context isolation bypass via Function.prototype.bind hijack
https://github.com/advisories/GHSA-h7rp-cf8h-j98x
- **electron** (low, dev-only) — Electron: Cross-origin iframe can position native autofill popup
https://github.com/advisories/GHSA-x8rc-wpg4-grpf
- **electron** (moderate, dev-only) — Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
https://github.com/advisories/GHSA-9pf5-hg6p-4pwp
- **electron** (low, dev-only) — Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
https://github.com/advisories/GHSA-pfmc-3mgc-p6fp
- **electron** (moderate, dev-only) — Electron: HTTP redirect followed into local file loader
https://github.com/advisories/GHSA-v64r-4m7r-3mvq
- **electron** (moderate, dev-only) — Electron: window.open features string controls some window options considered privileged
https://github.com/advisories/GHSA-v93f-fgjr-hjrj
Native audit tree
```
├─ electron
│ ├─ ID: 1136552
│ ├─ Issue: Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
│ ├─ URL: https://github.com/advisories/GHSA-v3j7-r9gq-3gjw
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <39.8.10
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5
│
├─ electron
│ ├─ ID: 1136559
│ ├─ Issue: Electron: Extension tab APIs operate across session boundaries
│ ├─ URL: https://github.com/advisories/GHSA-m55f-7gqj-fr98
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <39.8.8
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5
│
├─ electron
│ ├─ ID: 1136560
│ ├─ Issue: Electron: shell.openPath path validation bypass via embedded null byte
│ ├─ URL: https://github.com/advisories/GHSA-5c9j-mhmv-5xgx
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <39.8.6
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5
│
├─ electron
│ ├─ ID: 1136567
│ ├─ Issue: Electron: Context isolation bypass via Function.prototype.bind hijack
│ ├─ URL: https://github.com/advisories/GHSA-h7rp-cf8h-j98x
│ ├─ Severity: high
│ ├─ Vulnerable Versions: <39.8.9
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5
│
├─ electron
│ ├─ ID: 1136571
│ ├─ Issue: Electron: Cross-origin iframe can position native autofill popup
│ ├─ URL: https://github.com/advisories/GHSA-x8rc-wpg4-grpf
│ ├─ Severity: low
│ ├─ Vulnerable Versions: <39.8.8
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5
│
├─ electron
│ ├─ ID: 1136575
│ ├─ Issue: Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
│ ├─ URL: https://github.com/advisories/GHSA-9pf5-hg6p-4pwp
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <39.8.7
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5
│
├─ electron
│ ├─ ID: 1136579
│ ├─ Issue: Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
│ ├─ URL: https://github.com/advisories/GHSA-pfmc-3mgc-p6fp
│ ├─ Severity: low
│ ├─ Vulnerable Versions: <39.8.10
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5
│
├─ electron
│ ├─ ID: 1136590
│ ├─ Issue: Electron: HTTP redirect followed into local file loader
│ ├─ URL: https://github.com/advisories/GHSA-v64r-4m7r-3mvq
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <39.8.8
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5
│
├─ electron
│ ├─ ID: 1136597
│ ├─ Issue: Electron: window.open features string controls some window options considered privileged
│ ├─ URL: https://github.com/advisories/GHSA-v93f-fgjr-hjrj
│ ├─ Severity: moderate
│ ├─ Vulnerable Versions: <39.8.8
│ │
│ ├─ Tree Versions
│ │ └─ 23.3.0
│ │
│ └─ Dependents
│ └─ react-devtools@npm:6.1.5
│
```
Contributor guide
Research direction
No source file or test is named. Start with the linked CI run and Native audit tree, then identify the Electron dependency entry and the project's policy for dev-only advisories. Done should be defined as addressing the advisories or documenting why they require no change.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- electron, typescript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100