PT-2024-18977 · Sidequest · Sidequest
Coolcoolnoworries
·
Published
2024-01-04
·
Updated
2024-01-11
·
CVE-2024-21625
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SideQuest versions prior to 0.10.35
Description
The SideQuest desktop application uses deep links with a custom protocol (
sidequest://) to trigger actions in the application from its web contents. Due to improper sanitization of deep link URLs prior to version 0.10.35, a one-click remote code execution can be achieved when a device is connected and a user clicks a malicious link from within the application.Recommendations
For versions prior to 0.10.35, update to version 0.10.35 or later to resolve the issue, as the custom protocol links within the electron application are now being parsed and sanitized properly in this version. As a temporary workaround, consider avoiding clicking on links from within the application until the update is applied.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sidequest