Executive brief
NW.js is a framework for building desktop applications using web technologies. The package insecurely downloads runtime executables over plain HTTP, allowing an attacker in a privileged network position to intercept and replace the executable with malicious code, leading to complete system compromise during installation or updates.
Technical details
The vulnerability is a cleartext download issue (CWE-311) in the npm installer for NW.js. The install.js script constructs a download URL for the NW.js runtime executable using HTTP instead of HTTPS. An attacker with network-level access (man-in-the-middle position) can intercept the HTTP response and serve a malicious executable, achieving arbitrary code execution with the privileges of the user running npm install. The fix, released in version 0.23.6-1, changes the default download URL base from http://dl.nwjs.io to https://dl.nwjs.io. All versions prior to 0.23.6-1 are affected.
Affected products
- NW.js nw before 0.23.6-1
Timeline
- 2019-02-18: disclosed: GHSA advisory published
- 2016: patched: Fix released in version 0.23.6-1 via commit adb4df1