{"id":"CVE-2024-29900","aliases":["GHSA-34h3-8mw4-qw57"],"url":"https://o3.security/vulnerability/CVE-2024-29900","summary":"@electron/packager's build process memory potentially leaked into final executable","details":"Electron Packager bundles Electron-based application source code with a renamed Electron executable and supporting files into folders ready for distribution. A random segment of ~1-10kb of Node.js heap memory allocated either side of a known buffer will be leaked into the final executable. This memory _could_ contain sensitive information such as environment variables, secrets files, etc. This issue is patched in 18.3.1.\n","published":"2024-03-29T15:15:45.766Z","modified":"2026-08-12T03:51:34.682747977Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.00633,"percentile":0.48736,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@electron/packager","fixedVersion":"18.3.1"}],"fix":{"url":"https://github.com/electron/packager/commit/d421d4bd3ced889a4143c5c3ab6d95e3be249eee","label":"electron/packager@d421d4b"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/29xxx/CVE-2024-29900.json"},{"type":"ADVISORY","url":"https://github.com/electron/packager/security/advisories/GHSA-34h3-8mw4-qw57"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-29900"},{"type":"FIX","url":"https://github.com/electron/packager/commit/d421d4bd3ced889a4143c5c3ab6d95e3be249eee"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:34.682747977Z"}}