Executive brief
A vulnerability in the Electron application update utility can cause sensitive login credentials to be sent to untrusted third-party servers. When an application checks for updates, it may be redirected from a trusted source like GitLab to an external storage provider; during this process, the utility fails to remove certain security tokens from the request headers. An attacker who controls a redirect destination could capture these tokens to gain unauthorized access to private source code or release artifacts.
Technical details
A credential disclosure vulnerability exists in the HttpExecutor.prepareRedirectUrlOptions component of builder-util-runtime. The root cause is a case-sensitive property check that only identifies and deletes the exact lowercase 'authorization' header during cross-origin redirects. Other sensitive headers, such as 'PRIVATE-TOKEN' (used by GitLab) or mixed-case 'Authorization' keys, bypass this check and are forwarded to the new origin. An attacker can exploit this by observing or controlling the destination of a 3xx redirect during an update check to capture valid authentication tokens. The issue is fixed in version 9.7.0 of builder-util-runtime by implementing a case-insensitive, separator-agnostic header normalization and registry check.
Affected products
- electron-userland builder-util-runtime < 9.7.0
- electron-userland electron-builder < 26.15.0
Timeline
- 2026-06-16: disclosed
- 2026-06-30: advisory: NVD publication
- 2026-07-24: patched: GitHub Advisory reviewed and updated