evil-mad / robopaint

The software for your friendly painting robot kit!
127 stars 34 forks source link

Update electron for known critical severity security vulnerability #296

Open oskay opened 6 years ago

oskay commented 6 years ago

We have a headline-level security notice from github: https://github.com/evil-mad/robopaint/network/dependencies

docprofsky commented 6 years ago

Is it for CVE-2017-1000006?

oskay commented 6 years ago

CVE-2018-1000006

docprofsky commented 6 years ago

While searching, I also found an older RCE vulnerability, which is not fixed until 1.6.14 and 1.7.8. https://electronjs.org/blog/chromium-rce-vulnerability