Junglewise Threat Intelligence

CVE-2026-54673: Electron electron-builder credential leak via cross-origin redirects

CVE-2026-54673 · Severity: high · CVSS 4 · Published 2026-06-30

Technologies: Electron Userland Electron-Builder. Vendors: Electron Userland.

Executive brief

A vulnerability in the Electron application update utility can cause sensitive login credentials to be sent to untrusted third-party servers. When an application checks for updates, it may be redirected from a trusted source like GitLab to an external storage provider; during this process, the utility fails to remove certain security tokens from the request headers. An attacker who controls a redirect destination could capture these tokens to gain unauthorized access to private source code or release artifacts.

Technical details

A credential disclosure vulnerability exists in the HttpExecutor.prepareRedirectUrlOptions component of builder-util-runtime. The root cause is a case-sensitive property check that only identifies and deletes the exact lowercase 'authorization' header during cross-origin redirects. Other sensitive headers, such as 'PRIVATE-TOKEN' (used by GitLab) or mixed-case 'Authorization' keys, bypass this check and are forwarded to the new origin. An attacker can exploit this by observing or controlling the destination of a 3xx redirect during an update check to capture valid authentication tokens. The issue is fixed in version 9.7.0 of builder-util-runtime by implementing a case-insensitive, separator-agnostic header normalization and registry check.

Affected products

  • electron-userland builder-util-runtime < 9.7.0
  • electron-userland electron-builder < 26.15.0

Timeline

  • 2026-06-16: disclosed
  • 2026-06-30: advisory: NVD publication
  • 2026-07-24: patched: GitHub Advisory reviewed and updated

References

Related threats