PT-2024-18977 · Sidequest · Sidequest

Coolcoolnoworries

·

Published

2024-01-04

·

Updated

2024-01-11

·

CVE-2024-21625

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SideQuest versions prior to 0.10.35
Description The SideQuest desktop application uses deep links with a custom protocol (sidequest://) to trigger actions in the application from its web contents. Due to improper sanitization of deep link URLs prior to version 0.10.35, a one-click remote code execution can be achieved when a device is connected and a user clicks a malicious link from within the application.
Recommendations For versions prior to 0.10.35, update to version 0.10.35 or later to resolve the issue, as the custom protocol links within the electron application are now being parsed and sanitized properly in this version. As a temporary workaround, consider avoiding clicking on links from within the application until the update is applied.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-21625
GHSA-3V86-CF9Q-X4X7

Affected Products

Sidequest